Aon
Principal Security Penetration Tester, Cyber Solutions
Aon, Seattle, Washington, us, 98127
The Proactive Security Testing team is looking for motivated individuals to add to its team. We provide a challenging and exciting work environment that offers a healthy combination of autonomy and senior level support. Our team publishes books and security blogs, delivers conference talks, contributes to open-source software projects, and are engaged in a variety of continuous security research projects. Aon is in the business of better decisions. At Aon, we shape decisions for the better to protect and enrich the lives of people around the world. As an organization, we are united through trust as one inclusive, diverse team, and we are passionate about helping our colleagues and clients succeed. What the day will look like As a Principal Security Penetration Tester (termed internally as a "Security Testing Manager"), you will serve as a senior member of the penetration testing team. In addition, the person in the role will do the following: Perform penetration testing activities focused on assessing the security of web applications, mobile applications, APIs, and thick clients. Conduct complex hybrid web application security assessments, involving code review and dynamic application testing applying a combination of static and dynamic source code analysis techniques. Perform infrastructure penetration testing, including external/internal penetration testing, red teams, etc. Write test harnesses to help identify and proof-of-concept potential security vulnerabilities. Clearly communicate vulnerabilities to client development teams during and post-assessment. Document technical issues identified during security assessments, outlining the associated risks for clients, and providing tailored recommendations for remediation. Assist colleagues in pre-sales scoping activities for penetration testing engagements. Offer technical mentorship and career development guidance to junior engineers within the organization. Engage in vulnerability research to produce blog posts, conference talks, whitepapers, etc. Contribute to internal business operations by participating in and suggesting process improvements. Develop, update, and improve internal tooling used for reporting and penetration testing. Partner with the team in the recruitment of new penetration testing talent including reviewing resumes and conducting interviews. Skills and experience that will lead to success. 5+ years of hands-on penetration testing and/or bug bounty experience against web/mobile applications, above and beyond running automated tools. 5+ years of hands-on experience performing network/infrastructure penetration testing. Some expertise in development and/or source code review, focusing on languages such as Java, C#, C/C++, PHP, Ruby, Python, Go, Swift, Objective C/C++, Kotlin, etc. Up to date experience with testing techniques and tooling, such as Burp Suite and other fuzzers/proxies. Up to date experience with code review scanning tools, such as Fortify, Semgrep, etc. Deep knowledge of common software vulnerabilities, such as those described in the OWASP Top 10 and CWE/SANS Top 25. Possesses a solid grasp of Unix, Windows, and network security. Ability to work remotely as part of a distributed team and travel to client sites when required. Excellent communication skills (written & verbal) in English, to present complex technical topics concisely to both technical and business audiences. We do not offer visa sponsorship for this role. How we support our colleagues In addition to our comprehensive benefits package, we encourage a diverse workforce. Plus, our agile, inclusive environment allows you to manage your wellbeing and work/life balance, ensuring you can be your best self at Aon. Furthermore, all colleagues enjoy two "Global Wellbeing Days" each year, encouraging you to take time to focus on yourself. We offer a variety of working