About this role
Where Ambition Meets Innovation
At LPL’s Global Capability Center , you'll find a collaborative culture where your voice matters, integrity guides every decision, and technology fuels progress. Your skills, talents, and ideas will redefine what's possible. LPL's success reflects its exceptional employees, who together pursue one noble purpose: empowering financial advisors to deliver personalized advice for all who need it. We’re proud to be expanding and reaching new heights in Hyderabad.
Join us as we create something extraordinary together.
Job Overview:
As a member of the Cyber Security team, the Offensive Security Engineer will be responsible for managing the scheduling, scoping, and tracking of internal penetration testing and offensive security engagements.
This role will take the lead on ensuring that penetration test requests are scheduled, scoped, and completed within defined timeframes as well as assist with running the company’s Bug Bounty program and tracking associated findings from Offensive Security engagements.
The ideal candidate must be highly organized, able to track tasks at a detailed level, and able to manage multiple tasks in a streamlined manner as well as possess a technical skill set to understand findings and mitigation requirements.
Offensive Security is a top area of focus at LPL. This is an exciting time to join the Information Security team as we look for highly skilled people to help expand the current program.
Responsibilities:
- Manage the penetration testing schedule including monitoring ad-hoc requests and pre-defined assessments and assigning tests to the available testers to ensure that tests can be completed within acceptable timeframes
- Organize individual testing engagements by assisting with tester assignment, scoping, communication with application/asset owners and project management tracking to ensure that all stages of the test are completed within agreed up timeframes.
- Ensure that findings from performed tests are entered into the findings tracking system and communicated to impacted stakeholders.
- Track open findings by following up with assignees, gathering information around remediation plans, and producing reports and metrics around finding resolution status
- Manage the process of retesting and ensuring that open findings are adequately retested and remediated prior to issue closure
- Assist with the company’s Bug Bounty program by triaging submitted reports and entering validated findings into the findings tracking system and communicating to impacted stakeholders
What are we looking for?
We want collaborators who can deliver a world-class client experience. We are looking for people who thrive in a fast-paced environment, are client-focused, team oriented, and are able to execute in a way that encourages creativity and continuous improvement.
Requirements:
- 3+ years experience working in Information Security, with a focus on Vulnerability Management, Application Security, or Offensive Security
- 2+ years of project management related experience in tracking and coordinating significant work efforts with a large number of external dependencies
Preferences:
- Bachelor’s Degree or equivalent in Information Security, Engineering, or Computer Science.
- Experience working with JIRA and other work management tools
- Knowledge of common security vulnerabilities and corresponding remediation approaches
- Advanced understanding of OWASP, the MITRE ATT&CK framework, Atlas, and the software development lifecycle (SDLC).
- Knowledge of Linux/Mac/Windows operating systems, AWS/Azure cloud environments and cloud-native resources (ex. Containers, Kubernetes, microservices, serverless functions)
- Knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programing.
- Good communication skills and ability to working with all stakeholders, internal and external, finding, advising and implementing the best solutions.
- Strong organization skills
Core Competencies:
- Able to make quick decisions and resolve complex technical problems
- Ability to manage through shift changes and effectively transition open and unresolved issues.
- Ability to adapt, learn new technologies, develop new processes, and improve procedures.
- Excellent documentation skills.
- Ability to write, read, interpret, and edit complex documents and correspondence with team members and stakeholders.
- Excellent verbal and written communication skills.
- Ability to work peak, off-peak, weekend, and holiday shifts.
- Ability to communicate and respond to communication effectively with client, associates, and stakeholders.
- Ability to perform problem-solving, use logic and creative thought processes to resolve complex technical problems.
LPL Global Business Services, LLP - PRIVACY POLICY