Jobs and Careers
DI

Senior Penetration Tester

DigitalOcean
United States, United StatesRemotefull_timeVerifiedPosted 26 Apr 2024
💰 $192,000/yr($150,000/yr$192,000/yr)

About the role

Do you ever wonder what happens inside the cloud?

DigitalOcean (NYSE: DOCN) simplifies cloud computing so builders can spend more time creating software that changes the world. With our mission-critical infrastructure and fully managed offerings, DigitalOcean enables startups and small and medium-sized businesses (SMBs) to rapidly deploy and scale modern applications. As a remote-first organization, our employees, like our customers, are based around the world.

We want people who are passionate about making the internet a safer place for everyone.

We’re looking for a Senior Penetration Tester to lead an internal ethical hacking function that works collaboratively alongside engineering teams to uncover vulnerabilities and weaknesses in the enterprise and consumer product environments. We believe that finding an issue is only the beginning of our work; we value cross-team coalitions and collaboration with the business to find reasonable remediations and view this post-engagement collaboration as crucial to success. Your work will make our million+ customers more secure and will help ensure that DigitalOcean is a respected contributor to the broader security community.

As a member of the Security Engineering team, you will report to the Senior Manager of Product Security. You will collaborate with other security teams and the rest of DigitalOcean to plan, coordinate, execute, and report on sophisticated ethical hacking exercises, to identify software, network, and systems vulnerabilities, and reduce the risk posture of DigitalOcean’s systems. You will also be a primary driver of our vulnerability management program, leveraging your expertise to assess contextual impact from both your engagements and other internal and external sources. You will act as a primary point of contact with security researchers in our bug bounty program. Security at DO means solving incredibly complex problems at a high-scale that have real impact for our customers, our products, and for the larger internet community.

What you’ll be doing:

Perform penetration testing engagements and find vulnerabilities in software, systems, and networks (55%)

  • Develop tools, methodologies, and infrastructure to support penetration testing engagements
  • Set scope, objectives, and timelines for penetration testing engagements and leverage data to create useful metrics
  • Work with security and engineering teams to communicate findings, collaborate on recommendations, and inform key stakeholders
  • Provide holistic assessments of security layers across infrastructure, application, people, and process

Lead our bug bounty and vulnerability management programs (35%)

  • Act as the primary point of contact to security researchers engaged in our bug bounty program
  • Assess and triage new vulnerabilities to the vulnerability management program to determine contextual impact to the business
  • Educate security and engineering teams on topical vulnerability patterns, in coordination with teams such as fraud & abuse and threat intelligence

Cultivate and promote a security culture (10%)

  • Champion an internal security culture (developer training, internal CTFs, etc.)
  • Help DigitalOcean engineers understand how security events impact them. How does Retbleed impact DigitalOcean’s fleet? How should the company respond to the next xz-style backdoor?

There’s no coding expectation in this role beyond scripting common pentest tools, but if interested you will have the opportunity to collaborate with our wider Security Engineering team on creating paved roads and secure defaults, amongst other projects.

What we’ll expect from you:

Required qualifications:

  • 5+ years minimum, of job related experience pen testing web application and network services
  • Expert understanding of software security architecture and design, threat modeling, and mitigations for common application security issues
  • Ability to find and exploit security flaws in several of:
    • Go, React, GraphQL, PHP, and Python
    • Kubernetes and cloud environments
    • Memory and process isolation, e.g., kvm, gvisor, kata, namespaces, cgroups
    • Network protocols, e.g., BGP, Open VSwitch, BPF
  • A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity. Engineering teams are our partners, not our adversaries

Preferred qualifications:

  • 2+ years minimum, of job related experience pen testing services deployed in public cloud infrastructure
  • Familiarity with a variety of vulnerability and risk assessment frameworks, such a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

DigitalOcean

View company profile →