Security Penetration Tester

Xerox
United States
8 days ago
Apply on xerox.avature.net
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Burp Suite Computer Programming Imaging Technology Python (Programming Language) Kali Linux Nmap Open Web Application Security
+11 more
PCI Data Security Standards Windows PowerShell Red Team (Cyber Security) Secure Coding Security Software Web Applications Scripting Cloud Platform System Bug Reporting Metasploit Nessus

Job description

XCS (Xerox) is seeking a Penetration Tester with approximately 3 years of hands-on experience to join our Offensive Security team. In this role, you will identify, exploit, and help remediate security vulnerabilities across our applications, networks, and infrastructure through simulated attacks, contributing directly to the security posture of our products and enterprise environment., * Plan and execute penetration tests against web applications, networks, APIs, and cloud environments to identify exploitable vulnerabilities.

  • Perform manual and automated security testing using industry-standard tools (e.g., Burp Suite, Metasploit, Nmap, Nessus, Cobalt Strike).
  • Document findings clearly in professional reports, including risk ratings, reproduction steps, and remediation recommendations.
  • Collaborate with engineering and IT teams to validate fixes and re-test remediated issues.
  • Stay current on emerging threats, attack techniques, and vulnerability disclosures relevant to Xerox’s technology stack.
  • Support red team exercises, social engineering assessments, or physical security tests as needed.
  • Contribute to internal tooling, scripts, or playbooks that improve testing efficiency and coverage.
  • Assist with compliance-driven testing (e.g., PCI-DSS, SOC 2) as required.

Requirements

  • Approximately 3 years of professional experience in penetration testing, offensive security, or a closely related role.
  • Must be based in the United States and authorized to work in the U.S. without sponsorship.
  • Solid understanding of common vulnerability classes (OWASP Top 10, network-layer attacks, privilege escalation, etc.).
  • Hands-on experience with penetration testing tools and frameworks (Burp Suite, Metasploit, Nmap, Kali Linux, etc.).
  • Working knowledge of scripting/programming (Python, Bash, or PowerShell) for tooling and automation.
  • Strong written communication skills for producing clear, actionable technical reports.
  • Ability to work independently in a remote environment while collaborating across distributed teams.

Preferred Qualifications

  • Industry certifications such as OSCP, CEH, or GPEN (preferred, not required).
  • Experience testing cloud environments (AWS, Azure, or GCP).
  • Familiarity with secure code review or application security testing.
  • Prior experience in a regulated industry (e.g., government, healthcare, finance, or print/imaging technology).

Benefits & conditions

The salary range above represents the low and high end in the local currency of Xerox’s salary range for this position and is reflected in an annualized amount. Actual salaries, will vary based on factors including, but not limited to, geographic location, market competition, and/or the successful applicant’s education, experience, knowledge, skills, and abilities. The range listed is just one component of Xerox’s total compensation package for employees. Employees are also afforded a comprehensive suite of benefits, to view those details please visit Xerox Careers for your applicable country. If you are not reviewing this job posting on Xerox Careers, we cannot guarantee the validity of this posting. For a list of our current internal postings, please visit Xerox Careers.

About the company

For more than 100 years, Xerox has continually redefined the workplace experience. Harnessing our leadership position in office and production print technology, we’ve expanded into software and services to sustainably power the hybrid workplace of today and tomorrow. Today, Xerox is continuing its legacy of innovation to deliver client-centric and digitally-driven technology solutions and meet the needs of today’s global, distributed workforce. From the office to industrial environments, our differentiated business and technology offerings and financial services are essential workplace technology solutions that drive success for our clients. At Xerox, we make work, work. Learn more about us at www.xerox.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on xerox.avature.net
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

4:30 min

Evaluating developer experience constraints in native scripts

Steve Shadders · LIVE

Videos

See all

Related articles

See all