Security Assurance Penetration Tester
Get alerts for roles like this
More Security Assurance Penetration Tester roles in United States — straight to your inbox. No account needed.
Applying to this role? Tailor your résumé to this job description in one click, then download it clean — no watermark, no subscription.
Job Description
Are you a collaborative Penetration Tester looking to work for a mission driven global organization? About the role - This role supports the offensive security function within Elsevier's Security Engineering team.
You will perform hands-on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. This is a hands-on role for a motivated security professional eager to grow in a collaborative, fast-paced environment.
About the team - The Security Assurance team supports the third-party penetration testing program, security control validation, and ongoing offensive security testing activities.
Responsibilities
Tracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking. Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture.
Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices. Maintaining program documentation, test records, and reporting artifacts.
Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed. Performing peer review of penetration testing deliverables, including test plans, findings, and final reports.
Participating in scoping exercises and contributing to the selection of appropriate testing methodologies. Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
Assisting in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning. Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with framewo
Required Skills
Prepare to Win This Role
Everything you need to ace the interview and negotiate top-of-band compensation.