Quick Summary
Security Analyst, Penetration Testing
Join the Global Services team as a Penetration Testing Analyst to enhance client security posture using advanced technical skills and defense strategy knowledge. This role involves ethical hacking, attacking networks, and testing custom protocols in embedded devices. You will collaborate with Managed Services teams to provide tactical reports, triage security alerts, manage customer needs, and support incident response communication.
About the Role
The Penetration Testing Analyst's core responsibility is performing technical security testing across diverse targets and delivering daily tactical reports to customers. You will gain critical experience observing the evolving cyber threat landscape and helping clients remediate and mitigate prevalent threats.
Key Responsibilities:
- Perform technical testing against various targets, including network penetration testing (internal, external, and wireless), web application and API testing, and social engineering (on-premise and electronic).
- Consistently produce high-quality reports and conduct peer reviews of colleagues' work for accuracy.
- Assist in developing and creating Executive Briefings.
- Deliver timely reports to clients and external stakeholders.
- Translate complex technical concepts for non-security personnel.
- Demonstrate capability for fast-paced learning and managing solo engagements.
- Participate actively in industry conferences and professional organizations.
Required Skills & Experience:
- 3+ years in an active technical security role.
- Excellent written and verbal communication skills.
- Previous technical security consulting experience.
- Knowledge of modern penetration testing tools and methodologies.
- Strong knowledge of network, web-based application, and IEEE 802.11 security concepts.
- Knowledge of Windows/Linux/UNIX internals and the Internet protocol suite.
- Experience using interpreted languages (Ruby, Python, PHP, etc.) and knowledge of compiled languages (Java, C, C++, Assembly, etc.).
- Experience with social engineering techniques and tactics.
- A Bachelor’s degree in Computer Science, MIS, CIS, or a related field, or equivalent experience.
- Certifications such as GPEN, CPTS, or OSCP.
- The ability to ask for help.
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We achieve this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We are building a dynamic and collaborative workplace where new ideas are welcome.
Protecting over 11,000 customers against threats means we continuously push boundaries, as we have for the past 20 years. If you are ready to solve some of the toughest challenges in cybersecurity, we are ready to help you take command of your career. Join us.
#LI-BD1 #LI-Remote
Rapid7, Inc. is committed to fair and equitable compensation practices. The salary range for this role in the US is: $86,700.00 - $117,300.00 USD Annual. Salary ranges may vary based on geographical location. This range does not include variable/incentive compensation, equity, and benefits (where applicable/eligible).
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status, or any other status protected by applicable national, federal, state, or local law.


