Remote
Paylocity

Associate Penetration Tester

RemoteTechnology: Product Development & Technology

Description

The Associate Penetration Tester is responsible for verifying that our cloud based Software-as-a-Service (SaaS) web applications are secure. The role involves performing threat modeling, security assessments, and ethical hacking of our web applications. In addition, the Associate Penetration Tester will be producing reports that document the risk of vulnerabilities identified by security assessments and penetration tests for each product team and our auditors.

Are you the leader we are looking for?

Who you are:

  • Passionate about information security and privacy
  • An evangelist regarding the importance of information security
  • Well versed in security issues affecting financial service organizations as well as widespread data center operations, such as cloud and mobile technology solutions
  • Committed to an ongoing partnership with other high profile groups within the organization (e.g. software development) to insure information security objectives are being understood and embraced
  • Established presence within information security communities
  • Ability to anticipate problems and recommend decisive action
  • Excellent communication skills (both written and oral)
  • Ability to work collaboratively across the organization
  • Self-driven, creative, and resourceful

How we work:

  • Casual, collaborative environment which embraces and operates under our shared principles
  • Complete transparency with open, honest discussions about our progress
  • Close working relationships across all areas of the organization
  • Focus on outcomes and learning

What we offer:

  • A strong commitment to Information Security both financially and organizationally
  • An existing talented and passionate Information Security team
  • The chance to meaningfully contribute to a vast market opportunity
  • A collaborative environment where our security team is empowered to help steer the direction of the team
  • A place to contribute your security knowledge company-wide through forum panels with our product development team
  • Annual training allowance to learn new things and bring it back to the team.
  • Flexible remote work schedule
  • Employee Stock Purchase Program (ESPP) which enables employees to share in the long-term growth and future success of the company

Requirements

  • Preferred education equivalent to a Bachelor’s degree in Information Security or related Computer Science
  • Be passionate about information security and privacy
  • Ability to evangelize regarding the importance of information security
  • Possess excellent communication skills (both written and oral)
  • Be self-driven, creative, and resourceful
  • 0 to 2 years of experience in one of the following – software development, security testing, vulnerability assessment
  • Be familiar with TCP/IP and networking concepts
  • Knowledge of the software development lifecycle and the ability to create and read code in a modern object-oriented programming language (such as ASP.net/C# or Python) and writing SQL scripts and web code (HTML/JavaScript/etc.)
  • Be willing to demonstrate coding proficiency in 6 months from hire
  • Have basic understanding of OWASP Top 10, Testing Guide, ASVS and other software security best practices
  • Knowledge of penetration testing against a wide variety of application layer platforms, including web, mobile, thick client, and Reverse Engineering, above and beyond running automated tools
  • Basic understanding of REST API, Security Testing, DAST and SAST tools
  • Ability to perform both manual and automated code reviews
  • General understanding of some of the following security tools – Burp Suite, ZAP, SQLMap, SQLNinja, Metasploit, Nessus, Wireshark, nmap, tcpdump, OSINT, Recon-ng, mimikatz, responder, maltego, aircrack-ng, Cain and Abel, JTR, hashcat, hydra, SET, Nikto, dirbuster, golismero, theHarvester, BeEf, Sparta, wfuzz
  • Candidates with personal projects and opensource contributions will be preferred
  • Solid understanding of object oriented programming concepts

During the last three months, you would have:

  • Evaluated security threats, assess the potential impact to the business, and implement strategies to detect and generate alerts on Security incidents
  • Performed threat modeling, ethical hacking (both automated and manual), and security assessments on our web and mobile applications.
  • Worked collaboratively with IT and Software Development to continually improve our security posture.
  • Calculated risk and created reports that documented our current risk of vulnerabilities identified from penetration tests for a variety of product teams.
  • Handled escalations quickly and worked closely with our product teams to verify that any identified vulnerabilities are addressed.

At Paylocity, we create software that makes companies – especially their HR teams – better, faster, and stronger. We give clients the tools they need to make their companies run, and give our employees a rewarding company culture – all putting us in a category of our own. Join us and learn what makes us unique!

We’re a fast-growing company ready to revolutionize the payroll and HR world for hundreds of thousands of businesses by delivering innovative technology and support. We seek the best and brightest to help us create the future of our talent solutions – enabling our customers to better develop their employees. Our own employees are equally important to us: We work hard to provide the best work environment for our employees, and are dedicated to giving back to the communities in which we live and work.

Our award-winning culture has made this the place employees want to be. We have plenty of opportunities for you to grow your career within Paylocity, and offer benefits like Tuition Reimbursement so you can continue to learn and develop your skills. You could say our growth game is strong. We also reward hard work with a flexible, casual work environment and plenty of perks. From picnics, to game nights, to holiday parties, there’s no shortage of ways to have fun.

We also offer the following benefits and perks:

  • Comprehensive benefits (medical, dental, vision, 401k)
  • Paid Parental Leave
  • Ample volunteer opportunities and events
  • Health and wellness program
  • Stock purchasing options (NASDAQ: PCTY)

Visit Paylocity.com/careers to learn more about working at Paylocity. Also be sure to check out what past and present employees have to say about us and our CEO on Glassdoor.

At Paylocity, “We” is what makes us different. We are committed to fostering a culture that honors diverse opinions, perspectives, and backgrounds, knowing that each makes us stronger and collectively unbeatable together. We actively cultivate these differences as we engage each other in driving innovation in the software and services we provide our customers. Paylocity is an equal opportunity employer.