Quick Summary
As a Penetration Testing Analyst, you will join the Global Services team to enhance client security posture through your technical expertise and knowledge of defense strategies. You will engage in attacking networks and hacking custom protocols implemented in embedded devices. Additionally, you will collaborate with various Managed Services teams to deliver daily tactical reports to customers, triage alerts, address customer needs, and assist with incident response handling and communication.
About the Role
As a Penetration Testing Analyst, your primary responsibility involves performing technical testing against diverse targets and providing daily tactical reports to our customers. You will gain firsthand experience observing and learning about the evolving cyber threat landscape, helping customers remediate and mitigate prevalent threats.
Specifically, your focus will be to:
- Perform technical testing against a variety of targets, including network penetration testing (internal, external, and wireless), web application and API testing, and social engineering (on-premise and electronic).
- Consistently produce high-quality reports and peer-review colleagues' work for errors and inaccuracies.
- Help develop and create Executive Briefings.
- Deliver timely reports to clients and external stakeholders.
- Translate technical concepts and convey them to non-security personnel.
- Be capable of learning in a fast-paced environment and taking on solo engagements.
- Participate in industry conferences and professional organizations.
The skills and qualities you’ll bring include:
- 3+ years in an active technical security role.
- Excellent written and verbal communication skills.
- Previous technical security consulting experience.
- Knowledge of modern penetration testing tools and methods.
- Strong knowledge of network, web-based application, and IEEE 802.11 security concepts.
- Knowledge of Windows/Linux/UNIX internals and the Internet protocol suite.
- Experience using interpreted languages (Ruby, Python, PHP, etc.) and knowledge of compiled languages (Java, C, C++, Assembly, etc.).
- Experience with social engineering techniques and tactics.
- A Bachelor’s degree in Computer Science, MIS, CIS, or a related field, or equivalent experience.
- Certifications such as GPEN, CPTS, or OSCP.
- The ability to ask for help.
We believe that the best ideas and solutions emerge from multi-dimensional teams, reflecting diverse backgrounds and professional experiences. If you are enthusiastic about this role and believe your experience can make an impact, we encourage you to apply today.
#LI-BD1 #LI-Remote
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We achieve this by leveraging our collective expertise and passion to challenge possibilities and drive extraordinary impact. We are building a dynamic and collaborative workplace where new ideas are welcomed.
Protecting over 11,000 customers against malicious actors and threats means we continuously innovate, as we have for the past 20 years. If you are ready to tackle some of the toughest challenges in cybersecurity, we are here to help you advance your career. Join us.
Rapid7, Inc. is committed to fair and equitable compensation practices. A candidate’s salary is determined by various factors, including relevant work experience, skills, and certifications. We evaluate compensation decisions on a case-by-case basis, and it is not typical for an individual to be hired at the very top of the salary range.
The salary range for this role in the US is: $89,300.00 - 120,800.00 USD Annual
Salary ranges may vary based on geographical location. This range does not include variable/incentive compensation, equity, and benefits (where applicable/eligible).
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status, military service, or any other status protected by applicable national, federal, state, or local law.


