Penetration Testing Engineer, Cybersecurity
Ensemble Health PartnersAbout the role
Thank you for considering a career at Ensemble Health Partners!
Ensemble Health Partners is a leading provider of technology-enabled revenue cycle management solutions for health systems, including hospitals and affiliated physician groups. They offer end-to-end revenue cycle solutions as well as a comprehensive suite of point solutions to clients across the country.
Ensemble keeps communities healthy by keeping hospitals healthy. We recognize that healthcare requires a human touch, and we believe that every touch should be meaningful. This is why our people are the most important part of who we are. By empowering them to challenge the status quo, we know they will be the difference
The Opportunity:
The Penetration Testing Engineer, Cybersecurity will work as a member of the Cybersecurity Technical Assessments team. As a member of the team, you will be responsible for conducting penetration tests, vulnerability assessments, and reporting findings to detect both legacy and cutting-edge security vulnerabilities in enterprise environments. A strong understanding of networking, system administration and web application security is essential. We highly value the ability to think outside the box and go beyond conventional attack paths and exploits.
As a Penetration Testing Engineer, you will be responsible for supporting projects and operational teams by assessing, evaluating and verifying vulnerabilities identified in Ensemble’s environment. You will measure the risk and collaborate with appropriate stakeholders to efficiently remediate and mitigate these risks. Additionally, you will work with product, engineering, development, and security champions to integrate and automate security requirements, testing and verification into all aspects of the system development lifecycle. Duties may include:
- Scoping and performing penetration testing and vulnerability research of complex proprietary software and hardware for client services.
- Identifying and assessing vulnerabilities in systems and applications using both manual and automated testing methods to find and exploit code flaws, misconfigurations, and insecure software.
- Lending expertise in assisting with validation of Dynamic Application Security Testing (DAST) related findings.
- Keeping cybersecurity training and knowledge current by monitoring the latest security threats and vulnerabilities.
- Writing clear and concise penetration testing reports detailing findings and recommendations.
- Provide recommendations for remediation of identified vulnerabilities.
- Occasionally joining senior leaders or stakeholders on client kick-off and discovery sessions to answer questions from prospects and clients.
Job competencies:
- Strong knowledge of various operating systems and networks, especially experience with Linux, Windows, and Active Directory.
- Proficiency in a programming language such as Python, JavaScript, or .NET.
- Experience with penetration testing tools and frameworks such as Metasploit, Nmap, and Nessus.
- Knowledge of web application security, including experience with web application scanners and manual testing techniques.
- Experience with a variety of security tools and techniques and the ability to write scripts to automate tasks.
- Strong communication and report-writing skills.
- A degree or one recognized certification such as the CPTS penetration testing certification, CompTIA PenTest+, or OSCP is ideal but not necessary.
- Experience with cloud and container technologies like AWS, Azure, and Kubernetes is a plus.
Essential Job Functions:
- Leverage vulnerability management data to ensure the safety and integrity of the systems in which Ensemble applications are hosted.
- Conduct comprehensive penetration testing on networks, wireless systems, web applications, and other critical infrastructure.
- Generate reports and deliver presentations that explain the findings of research and vulnerability assessments.
- Participate in the creation of threat models for Ensemble developed systems.
- Coordinate purple team exercises to enhance detection and response capabilities, as well as test the functionality of security systems.
- Leverage tools commonly used to perform security testing (e.g., Nmap, Burp Suite, evilginx, hashcat, Metasploit, Nessus, impacket, C2 frameworks, nuclei, gophish, Dradis, Ghostwriter, etc.)
- Assist in opti
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s