Security Consultant – Penetration Testing, DevSecOps

Capgemini·Birmingham, Alabama·Posted 22d ago·via Talent.com

RegionUSA
Apply Now

Job description

Job Description: - Perform manual and automated penetration testing of web applications, APIs, mobile applications, cloud environments, and supporting infrastructure

  • Conduct reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities using OWASP, PTES, NIST, and MITRE ATT&CK methodologies
  • Identify vulnerabilities, validate exploitability, assess business risk, and provide actionable remediation recommendations
  • Execute security assessments of microservices, containers, Kubernetes, and cloud-native applications
  • Develop proof-of-concepts demonstrating security weaknesses and attack paths
  • Prepare detailed technical reports and executive summaries for customers and stakeholders
  • Integrate security controls and testing into CI/CD pipelines
  • Implement and manage SAST, DAST, SCA, IaC, Container Security, Secrets Detection, and API Security testing solutions
  • Collaborate with development teams to remediate vulnerabilities and adopt secure coding practices
  • Participate in security architecture reviews, threat modeling exercises, and secure design assessments
  • Automate security testing and compliance validation within DevOps toolchains
  • Develop security guardrails and policy-as-code capabilities
  • Perform vulnerability triage, risk prioritization, and remediation tracking
  • Support continuous security monitoring and risk assessment activities
  • Analyze emerging threats, attack techniques, and security trends
  • Assist in developing security standards, procedures, and best practices
  • Work with engineering, cloud, and infrastructure teams to enhance organizational security posture
  • Present findings and recommendations to developers, architects, engineering teams, and leadership
  • Provide security consulting throughout the software development lifecycle

Requirements: - Bachelor's degree in Computer Science, Information Security, Engineering, or a related field

  • 5-8 years of hands-on cybersecurity experience
  • Minimum 3+ years of experience conducting application and API penetration testing
  • Experience implementing or supporting DevSecOps initiatives within CI/CD environments
  • Strong understanding of Web Application Security, API Security, Secure SDLC, OWASP Top 10, OWASP API Top 10, MITRE ATT&CK, Threat Modeling, and Vulnerability Management
  • Hands-on experience with Burp Suite Professional, Nmap, Nessus / Qualys / Tenable, Metasploit, Kali Linux, Checkmarx, Veracode, Snyk, SonarQube, and GitHub Actions / Azure DevOps / Jenkins
  • One or more listed security certifications: OSCP, CRTO, PNPT, CEH, GWAPT, GPEN, CISSP, CCSP, Azure Security Engineer Associate, or AWS Security Specialty
  • Experience with container security (Docker, Kubernetes)
  • Experience conducting cloud penetration testing
  • Understanding of Infrastructure as Code (Terraform, CloudFormation)
  • Familiarity with Red Team methodologies and adversary simulation
  • Exposure to Zero Trust Architecture and Secure-by-Design principles
  • Experience with AI/LLM security testing is a plus
  • Excellent communication, consulting, and stakeholder management skills

Benefits: - Vacation: 12-25 days, depending on grade

  • Company paid holidays
  • Personal Days
  • Sick Leave
  • Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)
  • Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)
  • Life and disability insurance
  • Employee assistance programs
  • Other benefits as provided by local policy and eligibility
  • Variable incentives, bonuses, or commissions may be available

first seen 2026-09-16 21:30:01 · last verified 2026-09-16 21:30:01


pentestcareers.com // breach the job market

Security Consultant – Penetration Testing, DevSecOps at Capgemini | Pentest Careers