About Coalfire
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
But that’s not who we are – that’s just what we do.
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
What You'll Do
- Working independently and collaboratively with a team to both lead and support
- Perform penetration testing on applications with complex technology stacks from both a: Blackbox and Whitebox perspective
- Dynamically flex your skills when assessing emerging or custom technologies.
- Contextualize vulnerabilities and assess realistic impact to a client accounting for mitigating and aggravating factors.
- Manage priorities and tasks to achieve utilization targets.
- Operate with professionalism both internally and with clients.
- Ensure quality reports and services are delivered efficiently and on time.
- Maintains strong depth of knowledge in the practice area.
- Collaborate with project managers, quality management
What You'll Bring
- Application penetration testing and assessment tradecraft and methodologies (including browser-based, API)
- Working knowledge of at least two programming or scripting languages
- Strong understanding of security principles and industry best practices.
- Minimum of 2 years’ experience in a consulting/professional services role
- Minimum of 2 years’ experience in Application Security and/or Software Development
- Strong consulting skills including: Time management, performing adjacent tasks while ensuring on-time delivery, escalating issues as needed
- Verbal communication, leading client calls for project kickoffs and debrief
- Written communication
- Report writing, for both executive audiences and technical staff
- Proficiency in Web Application Penetration Testing
- Strong overall technical skills, with additional strong expertise in at least one of the following preferred:
- Mobile Application Penetration Testing
- Thick Application Penetration Testing
- Hardware Penetration Testing
- Secure Code Review
- Container Penetration Testing
- Cloud Penetration Testing
- Network Active Directory Penetration Testing
- AI Penetration Testing
Bonus Points
- AWAE, OSCP, OSCE, OSEE offensive security certifications
- Development and engineering backgrounds
- Cloud Service penetration testing tradecraft and methodologies across multiple service providers (e.g. AWS, GCP, etc.).
- Mobile platform and application penetration testing tradecraft and methodologies across both iOS and Android.
- Social engineering in all its forms.
- AWS Certified Security, AWS Certified Advanced Networking, AWS Certified SysOps Administrator
- Network, Database, System administration experience and certifications