Senior Associate - Penetration Testing - Chicago, IL or Remote, USA
Urbane Security · Chicago, IL · 3 days ago
OTHR$125k–$195k/yrFull-time
About
Urbane is seeking experienced penetration testers to join our Security Services teams. We work with the largest and most interesting organizations globally, addressing complex security challenges.
Responsibilities
- Assess real-life risks to diverse technical environments by identifying security weaknesses and actively exploiting them.
- Determine additional impact through post-exploitation activities.
- Assist with black box network testing, insider threat assessments, credentialed application exploitation, and testing the effectiveness of human and physical controls.
- Provide guidance on defensive designs and assist compliance associates on difficult technical choices.
- Occasionally switch sides to maintain a full perspective of the security landscape.
Requirements
- 4+ years of experience in penetration testing, either consulting or internal.
- Performed one or more of the following roles as a penetration tester: external network penetration testing, internal network penetration testing, wireless penetration testing, web application penetration testing, mobile application penetration testing, IOT device penetration testing, non-destructive physical security testing.
- Gained a strong technical knowledge and understanding of mixed-technology environments, including diverse operating systems, network hardware, web application languages, administration technologies, authentication mechanisms, and cloud platforms.
- Extensively used open source penetration testing tools and frameworks, such as Metasploit, Burp, Nmap, etc.
- Developed or modified tools in scripting languages, such as Ruby, Python, GoLang, Perl, or Java, to assist in testing a problem.
- Learned the core fundamentals of computers, all the way down to protocol stacks.
- Paid enough attention in English class to write good (or is it well?) and know to self-QA deliverables before sending them to others.
Qualifications
- College or equivalent educational experience preferred.
- Experience in modifying or creating tools or payloads to exploit vulnerabilities not effectively covered in other exploitation frameworks.
- Performed independent research, testing, or tool development on security issues out of curiosity.
- Active in industry groups (e.g., OWASP, DEF CON Groups, City-Sec Meetups, or other security meetups) and/or conferences (e.g., DEF CON, BlackHat, Summercon, THOTCON, WWHF, BSides, etc.).
- Utilized AI as a tool, but not a testing replacement, to improve coverage and efficiency.
Skills
- Strong technical knowledge and understanding of mixed-technology environments.
- Extensive use of open source penetration testing tools and frameworks.
- Experience in developing or modifying tools in scripting languages.
- Knowledge of core fundamentals of computers, including protocol stacks.
- Ability to write clear and well-organized deliverables.
- Experience in modifying or creating tools or payloads to exploit vulnerabilities.
- Independent research and testing experience.
- Experience with AI tools for improving coverage and efficiency.
Benefits
- Standard benefit packages, including Medical/Dental/Vision, paid vacation time, 401k plan, and reimbursable internet/phone/gym plans.
- Training and professional development stipends (yes, this includes conferences!).
- Annual team meetings and occasional team events, including BlackHat / DEF CON week.
- Exotic Travel Locations (like Arkansas!)
- Captivating challenges, meaningful work, and ability to grow, both intellectually and within the company.
Pay
$125,000 - $195,000/year (depending on knowledge, experience, and location).
Schedule
Currently less than 25% domestic/international travel, but subject to fluctuation.