Jobs and Careers
OC

Lead Associate Principal, Penetration & Vulnerability Testing

OCC
Remote, United States, United StatesRemotefull_timeVerifiedPosted 20 Jun 2025
💰 $229,500/yr($139,700/yr$229,500/yr)

About the role

Summary

This role will work collaboratively with the Security Penetration Testers to develop continuous testing automation tools that will increase OCC's security posture against all threats that put OCC’s organizational operations, assets or individuals at risk. The Security Penetration Testing Team engages in threat intelligence gathering, security control validation testing, firewall rule reviews, expedited and emergency change reviews, network penetration testing, web application penetration testing, mobile device testing, and more. Team members must ensure the availability and integrity of OCC’s operational systems and self-disclose identified findings in a timely/proactive manner.

This individual will primarily work with the OCC Security Penetration Team to help plan, design, and develop the infrastructure and custom code necessary to automate OCC’s current security control validation related activities.  This role will also assist with performing ad-hoc white-box penetration testing work of OCC’s infrastructure that is still currently in Development, or in need of pre-Production penetration testing. The position will involve interaction with multiple teams such as Security Architecture, Cyber Defense, Security Assurance, and various other Security and IT teams to coordinate white-box penetration testing engagements and re-test remediated Adversarial Red Team findings.

The ideal candidate will have Full Stack Developer experience with a strong enthusiasm for Security.  Experience building Cloud infrastructure for testing, and custom scripting expertise in at least one proficient language is required. This candidate must be driven, an excellent communicator, and have the enthusiasm to learn and stay ahead of today’s emerging threats and MITRE attack techniques.


Responsibilities

  • Collaborating with others to deliver complex projects which may involve multiple systems
  • Develop solutions to complex technical challenges while coding, testing, troubleshooting, debugging, and documenting the systems you develop
  • Optimize application performance through analysis, code refactoring, and system tuning
  • Recommend technologies and tools that improve the efficiency and quality of OCC’s systems and development processes
  • Conduct ad-hoc white-box penetration testing work of OCC’s infrastructure that is still currently in Development, or in need of pre-Production penetration testing.  These Penetration Testing activities may include Threat Intelligence Gathering, Network/Operating System/Application Penetration Testing, Web Application Penetration Testing, Mobile Application Testing, and more
  • Build security-hardened Cloud testing assets to use for external security control validation testing purposes
  • Coordinate with IT owners to re-test and validate remediated Red Team findings
  • Execute Open Source Intelligence Collection and Analysis Techniques (OSINT); leverage available resources and develop custom tools
  • Understand vulnerabilities and develop relevant exploits/payloads for use during Penetration Test activities
  • Perform security risk assessment, threat analysis and threat modeling
  • Perform reviews of OCC’s security, network, and applications in collaboration with Security Architecture and other OCC Security teams
  • Stay on-time, on-budget, and within scope of testing activities
  • Develop clear detailed reports and recommendations based on concrete evidence
  • Debrief users and provide remediation strategy on findings
  • Ensure alignment of security controls in OCC’s testing program and supporting services and related policies and procedures with applicable regulations and industry standard best practices
  • Assist management with the improvement of policies and procedures to support Security Testing activities as well as other security duties which may arise
  • Participate in developing a security roadmap, adopt security best practices, and implement new ideas and innovations according to the industry trends
  • Adhere to the best practices and work for delivering secured and quality products
  • Consult with technical experts and system owners on all aspects of Information Security and Compliance
  • Work closely with Production Support staff, Incidence Response, and IT infrastructure to increase organizational security posture
  • Support OCC’s security objectives and remediation efforts relating to Security Testing.
  • Supports and successfully completes Audits
  • Cross-train the other Security Penetration Testers and Adversarial Red Team members.
  • Cross-train other teams within Security Services and OCC IT departments to provide subject matter knowledge of a specific adversarial threat/risk, or to assist with remediation path recommendations
  • Participate in “Lessons

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

OCC

View company profile →