Full Time

Penetration Testing Operations Lead - Capital Group - Irvine, CA

Capital Group

Irvine, CA
Posted 7 days ago

Penetration Testing Operations Lead As the Penetration Testing Operations Lead you are an individual contributor in the Capital Group (CG) AppSec / Penetration Testing team. The CG AppSec team is part of Information Security in CG\'s Information Technology Group. In the role you will be helping us drive improvements in the systems and processes that support our penetration testing function to undertake exciting attacks and improvements. You will be responsible for coordinating and communicating with the key technology / business stakeholders for delivery of security assessments and advising on technology risks and mitigations. This role is hybrid (in-office 3 days/week) and can be in Irvine CA or New York NY depending on candidate current location and/or preference. In addition, you will be responsible for: Owning programs of work which drive improvements across enterprise systems and processes, identifying challenges and pain points, and providing novel approaches of solving them. Providing technical solutions to day-to-day challenges using existing internal/external technologies. Supporting our data-driven approach by gathering, analyzing, and presenting data gathered from a range of internal systems to identify areas of improvement and recommend solutions. Supporting penetration testers (both internal and third party) in operational support request and progression of the service. Acting as a technical leader in penetration testing function, engaging with stakeholders across the business to drive collaborative improvement efforts that enhance the security of our products and services. Analyzing penetration testing results and preparing detailed reports documenting identified vulnerabilities, their potential impact, and recommended remediation actions. Working closely with cross-functional teams across technology, infrastructure, business including developers, system administrators, and business stakeholders to prioritize and address security findings. Keeping up