- Expertini Resume Scoring: Our Semantic Matching Algorithm evaluates your CV/Résumé before you apply for this job role: Penetration Tester, Offensive Security Operations (Network/Cloud/Application) USDS.
Urgent! Penetration Tester, Offensive Security Operations (Network/Cloud/Application) - USDS Job Opening In New York – Now Hiring TikTok
About the TeamThe USDS Offensive Security and Privacy serves as the Independent Testing and Validation pillar for USDS.
The team performs cyber threat simulations within the TikTok USDS environment to proactively identify vulnerabilities, misconfigurations and defense gaps.
They do so by analyzing the organization's attack surface, which includes - but is not limited to - products, applications, controls, appliances, and infrastructure.
Their objective is to emulate adversaries to equip the organization against emerging threats by improving their identification, detection, protection, response, and remediation capabilities.
As an Application Security Penetration Tester, you will validate security controls around web resources and mobile applications and their backend web services for TikTok.
Work with a team of security testing professionals to enhance existing services offerings and security testing capabilities and conduct hands on technical testing focused on identification of OWASP type vulnerabilities in both web application and mobile applications.
To succeed in this role the candidate will possess breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programing.
All Application Security Penetration Testers are expected to continuously improve their tradecraft through research, to add breadth and depth to their knowledge.
In order to enhance collaboration and cross-functional partnerships, among other things, at this time, our organization follows a hybrid work schedule that requires employees to work in the office 3 days a week, or as directed by their manager/department.
We regularly review our hybrid work model, and the specific requirements may change at any time.
Responsibilities
- Develop/modify custom tooling to solve new needs
- Build relationships with engineering teams to strengthen TikTok's to security state
- Conduct full exploitation operations in Windows and *nix environments
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences
- Communicate findings and strategy to client stakeholders, including technical staff, executive leadership, and legal counsel
- Perform innovative research and promote an environment of innovation and knowledge sharing
- Perform web application testing, mobile application testing, network penetration testing, and source code reviews
- Utilize attacker tools, tactics, and procedures to perform analysis and identify vulnerabilities
- Implement static and dynamic security testing as part of an automated application security testing process
- Other Cybersecurity operational and project initiatives responsibilities to be assigned
Minimum Qualifications
- Bachelors’ Degree or industry equivalent work experience in IT, Computer Engineering or a similar field
- 3+ years of experience performing application penetration tests
- Well-rounded background in application, network, and system security
- Experience with using, administering, and troubleshooting different flavors of Linux + Window
- Experience with reading, writing, and editing code written in various programming languages, such as Perl, Python, Ruby, Bash, C/C++, C#, and Java
- Experience with Burp Suite Pro, including identification and usage of relevant plugins
- Experience with security assessment tools, including Nessus, Accunetix, Metasploit, or Cobalt Strike Preferred Qualifications:
- Industry certifications such as OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN
- Contributions to the security community such as research, public CVEs, bug-bounty recognitions, open-source projects, blogs, publications, etc
- Experience with server administration, TCP/IP networking, vulnerability identification and exploitation, vulnerability exploit code development, offensive security operation coordination and communication, vulnerability tracking and remediation, mobile testing
- Experience with methodologies on both static and dynamic analysis for different application types and platforms
- Experience working with Web Application Firewalls
- Securing, testing, having a good understanding of API vulnerabilities and how to address them
✨ Smart • Intelligent • Private • Secure
Practice for Any Interview Q&A (AI Enabled)
Predict interview Q&A (AI Supported)
Mock interview trainer (AI Supported)
Ace behavioral interviews (AI Powered)
Record interview questions (Confidential)
Master your interviews
Track your answers (Confidential)
Schedule your applications (Confidential)
Create perfect cover letters (AI Supported)
Analyze your resume (NLP Supported)
ATS compatibility check (AI Supported)
Optimize your applications (AI Supported)
O*NET Supported
O*NET Supported
O*NET Supported
O*NET Supported
O*NET Supported
European Union Recommended
Institution Recommended
Institution Recommended
Researcher Recommended
IT Savvy Recommended
Trades Recommended
O*NET Supported
Artist Recommended
Researchers Recommended
Create your account
Access your account
Create your professional profile
Preview your profile
Your saved opportunities
Reviews you've given
Companies you follow
Discover employers
O*NET Supported
Common questions answered
Help for job seekers
How matching works
Customized job suggestions
Fast application process
Manage alert settings
Understanding alerts
How we match resumes
Professional branding guide
Increase your visibility
Get verified status
Learn about our AI
How ATS ranks you
AI-powered matching
Join thousands of professionals who've advanced their careers with our platform
Unlock Your Penetration Tester Potential: Insight & Career Growth Guide
Real-time Penetration Tester Jobs Trends in New York, United States (Graphical Representation)
Explore profound insights with Expertini's real-time, in-depth analysis, showcased through the graph below. This graph displays the job market trends for Penetration Tester in New York, United States using a bar chart to represent the number of jobs available and a trend line to illustrate the trend over time. Specifically, the graph shows 2074 jobs in United States and 52 jobs in New York. This comprehensive analysis highlights market share and opportunities for professionals in Penetration Tester roles. These dynamic trends provide a better understanding of the job market landscape in these regions.
Great news! TikTok is currently hiring and seeking a Penetration Tester, Offensive Security Operations (Network/Cloud/Application) USDS to join their team. Feel free to download the job details.
Wait no longer! Are you also interested in exploring similar jobs? Search now: Penetration Tester, Offensive Security Operations (Network/Cloud/Application) USDS Jobs New York.
An organization's rules and standards set how people should be treated in the office and how different situations should be handled. The work culture at TikTok adheres to the cultural norms as outlined by Expertini.
The fundamental ethical values are:The average salary range for a Penetration Tester, Offensive Security Operations (Network/Cloud/Application) USDS Jobs United States varies, but the pay scale is rated "Standard" in New York. Salary levels may vary depending on your industry, experience, and skills. It's essential to research and negotiate effectively. We advise reading the full job specification before proceeding with the application to understand the salary package.
Key qualifications for Penetration Tester, Offensive Security Operations (Network/Cloud/Application) USDS typically include Computer Occupations and a list of qualifications and expertise as mentioned in the job specification. Be sure to check the specific job listing for detailed requirements and qualifications.
To improve your chances of getting hired for Penetration Tester, Offensive Security Operations (Network/Cloud/Application) USDS, consider enhancing your skills. Check your CV/Résumé Score with our free Resume Scoring Tool. We have an in-built Resume Scoring tool that gives you the matching score for each job based on your CV/Résumé once it is uploaded. This can help you align your CV/Résumé according to the job requirements and enhance your skills if needed.
Here are some tips to help you prepare for and ace your job interview:
Before the Interview:To prepare for your Penetration Tester, Offensive Security Operations (Network/Cloud/Application) USDS interview at TikTok, research the company, understand the job requirements, and practice common interview questions.
Highlight your leadership skills, achievements, and strategic thinking abilities. Be prepared to discuss your experience with HR, including your approach to meeting targets as a team player. Additionally, review the TikTok's products or services and be prepared to discuss how you can contribute to their success.
By following these tips, you can increase your chances of making a positive impression and landing the job!
Setting up job alerts for Penetration Tester, Offensive Security Operations (Network/Cloud/Application) USDS is easy with United States Jobs Expertini. Simply visit our job alerts page here, enter your preferred job title and location, and choose how often you want to receive notifications. You'll get the latest job openings sent directly to your email for FREE!