





Tier-1 brand, mid-level role, metro location, and generalist security skillset create high applicant competition.
Security and compliance specialization (PCI, CDE) create strong domain bias, reducing cross-industry transferability.
Explicit 4+ years, required technical skills, and preferred security certifications make screening highly strict.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead and perform manual and automated penetration tests on application-layer and network-layer components across cloud infrastructure.
Validate security controls, prioritize remediation efforts, and verify vulnerability fixes through re-testing and post-remediation assessments.
Collaborate with third-party security firms and manage compliance with regulatory requirements including PCI DSS and SOC.
Minimum 4+ years of hands-on experience in penetration testing, ethical hacking, or application security engineering.
Proficiency in security testing tools like BurpSuite Enterprise, SAST, DAST, and IAST, and scripting/programming languages such as Python, Go, Ruby, or Bash.
Deep understanding of web application vulnerabilities and network security concepts including TCP/IP, DNS, HTTP/S, TLS, IPSEC.
Relevant certifications such as OSCP, CEH, OSWE, or CISSP.
Experienced in managing or triaging public bug bounty programs is a plus.
Familiarity with cloud orchestration, Infrastructure as Code, containerization (Docker, Kubernetes), and security automation using ChatOps/Slack.
Understanding of compliance frameworks like ISO 27001, PCI DSS, SOC2, or CCPA to ensure regulatory security adherence.