United States
18 hours ago
Penetration Tester 3

As part of Oracle Customer Success Services, Risk Management & Security Services organization's mission is to increase Oracle’s value potential in the security services market by providing a managed security and compliance center of excellence that draws together the existing Oracle Tooling, Cloud Services and Oracle Professional Services to build a holistic thoughtful Security and Compliance Offering tailored to the customers' needs in the Hybrid cloud environment. We manage security across a vast array of customer environments- small business, global enterprise, government, and everything in between.

We are looking for experienced penetration testers with the enthusiasm and maturity to develop themselves further and join us in pushing our global team’s capabilities to a new level. A track record of self-education and an ability to adapt comfortably to change is necessary, and we'll do our part by providing regular formal training to keep your skills and certifications up to date.

Sharing knowledge and working eagerly with a team is key to success here, and you will lead our pentesting platforms, tooling and evolving comprehensive methodologies. This is an exciting chance to bring your skills to a global Cloud program!

A Glimpse At Our Toolkit:

Information Gathering & Scanning Phase: we use a variety of tools including: Nmap, Socat, Burpsuite Pro, Nessus, Qualys, WebInspect, Paros, CryTool, HTTPLiveHeaders, sqlmap and others to map assets and services in the larger environment.

Penetration Testing Phase: You'll devise and execute the pen test attack plan using human engineered, multiple exploits (Eg. missing patches and service mis-configurations, recognized attack vectors, etc). Tools we may use include: Webscarab Proxy, Medusa, Hydra, CrowBar, Metasploit, publicly available exploit code, proprietary and self-authored tools, and manual testing.

Reporting & Remediation: You'll be responsible for concluding your findings with a report to the Security Manager. This will be leveraged with the customer and other Oracle teams for remediation recommendations.

What the Penetration Tester/Pentester/Ethical Hacker will do:
   • Conduct network and server layer penetration testing against Oracle Cloud customers and internal systems
   • Conduct application-layer penetration testing against Oracle Cloud customers’ software applications and webservices deployed globally
   • Conduct penetration testing of new Oracle solutions deployed internally to support Oracle customers as part of  the Corporate Security Solution Assurance Process.
   • Conduct rigorous penetration testing of Oracle’s latest generation Cloud Services  (SaaS, PaaS, IaaS)
   • Document technical issues identified during security assessments, and author formal customer-facing reports
   • Follow up on implementation of corrective actions from assessments
   • Research security threats and attack vectors
   • Develop novel tooling and techniques to enhance the team’s platform and capabilities
   • Perform special security projects on an ad-hoc basis

What we want to see in the Penetration Tester/Pentester/Ethical Hacker:
• Established professional or military experience with Penetration testing/ethical hacking (3+ years preferred)
• Curiosity about learning anything that has to do with discovering vulnerabilities and exploiting them
• Professional certification: CEH, OSCP, OSCE/ OSWE or equivalent
• Solid education in Information Security and technical aspects thereof, CISSP certification preferred
• Hands-on experience with systems development, systems administration, or network administration, 2-5+ years ideal
• Hands-on experience in automated and manual penetration testing (infrastructure and web app/ service), 2-5+ years ideal
• Knowledge of Information Security standards and access controls such as ISO27001/2 and PCI DSS
• Good interpersonal skills and diligent, able to handle concurrent assignments
• Self-starter and self-sufficient, doesn’t need to be micro-managed

What will make you stand out:
• Self-educated, self-starters do well in this team, where passion and individual pursuits will be complemented by training and mentorship
• Personable, open, and collaborative approach coupled with precise independent execution skills and creativity
• Professional or extensive hobby experience with x86/x64 assembly, Java, Python, Ruby, Lua, or Go
• Professional experience building web applications, software, or systems engineering
• Knowledge of container platforms including Docker and Kubernetes
• CEH, OCSP, GPEN, GXPN, or other related certifications
• Understanding of reverse engineering, malware, debuggers, kernel memory layout in Windows and Linux
• Scripting/ programming experience (BASH, PowerShell, Python, C, Assembler) is an advantage
 

Career Level - IC3

Confirm your E-mail: Send Email
All Jobs from Oracle