> Markdown version of [/jobs/ext/2737339-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/2737339-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Unisys - **Location:** Philadelphia, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Burp Suite, C Sharp (Programming Language), Cipher, Code Review, Cyber Security, Information Systems, Computer Programming, Mobile Application Software, Kali Linux, Network Security, Network Architecture, Network Protocols, Nmap, Open Web Application Security, Windows PowerShell, Penetration Tools, Reverse Engineering, Web Applications, Wireless Networks, Scripting, Mitre Att&ck, Metasploit, Nessus - **Published:** September 5, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/63007758/1 ## About the Role * Bachelor's Degree from an accredited college or university (or additional eight (8) years of related experience in lieu of degree) required. * High degree of experience with the following technologies: + Cobalt Strike, Kali Linux + PowerShell, C#, GhostPack, Bloodhound + Metasploit, Metasploit Pro + Nmap, Burp Suite, Nessus, Netsparker * Certifications in CEH, LPT, OSCP and CEPT are a nice to have. * Ability to successfully interface with clients (internal and external). * Ability to document and explain technical details in a concise, understandable manner. * Ability to manage and balance own time among multiple tasks, and lead junior staff when required. * Experience with utilizing penetration testing frameworks such as MITRE ATT&CK & OWASP. * Excellent communication and interpersonal skills. ## Description * To be a key technical resource for various projects and IT teams, to provide sign off for testing documentation, or to assist in the testing solutions. * To lead the evaluation of target systems, including developing threat models, conducting security analysis and testing, demonstrating vulnerabilities and documenting the results. * Perform assessments of different types of information systems (web, OS, mobile, IoT, etc.) and networks to determine the effectiveness of defense-in-depth architecture against known vulnerabilities based on policies and industry best practices. Works with stakeholders, assists with remediation solutions, and compares and contrasts various system attack techniques and develops operationally effective countermeasures. Additional Responsibilities will include: * Perform network penetration and manipulation of network infrastructure; web and mobile application testing; source code reviews; threat analysis; wireless network assessments; and social-engineering assessments. * Scripting or automation of simple tasks using various scripting and programming tools as needed. * Developing, extending, or modifying exploits, shellcode or exploit tools. * Reverse engineering malware, data obfuscators, or ciphers. * Strong knowledge of tools used for wireless, web application, and network security testing. * Thorough understanding of network protocols, data on the wire, and covert channels. * Performs penetration testing using standard penetration tools (Metasploit, Nmap, Nessus, Burp Suite, etc.). * Perform information technology security research to remain current on emerging technology trends and develop exploits for disclosed and undisclosed vulnerabilities. * Contributes to developing and implementing tools for penetration testing and early warning of weaknesses or possible incidents building on methodologies as promulgated by NIST, ISO, etc. to ensure useful, measurable, and repeatable methods applied to quantifying risk. * Selects, installs, and configures security testing platforms and tools or develop tools and procedures for penetration tests. * Provide regular risk briefings to senior management on findings and develop remediation approaches and recommendations to improve cybersecurity posture. * Conduct hands-on technical testing beyond automated tool validation, including full exploitation and leveraging of access within multiple environments, such as Windows or Unix/Linux. * Conduct scenario-based security testing or red teaming to identify gaps in detection and response capabilities. * Develop comprehensive and accurate reports and presentations for both technical and executive audiences. * Effectively communicate findings and strategy to client stakeholders including technical staff and executive leadership. * Recognize and safely utilize attacker tools, tactics, and procedures. * Develop scripts, tools, or methodologies to enhance red teaming processes. * Assist with scoping prospective engagements, leading engagements from kickoff through remediation, and mentoring less experienced staff. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)