Rapid7 logo
Rapid7 Verified
Cybersecurity

Security Analyst, Penetration Testing

Massachusetts, Massachusetts, United StatesOnsiteFull Time$89,300–$120,800 /yrPosted 2 months agoVisa sponsorship available

Is this role right for you?

Upload your resume and get a skill-by-skill breakdown — see exactly where you match, where you're close, and what to highlight. Not a mystery percentage.

Get a tailored resume highlighting what this role needs.

Role summary

The Security Analyst, Penetration Testing role on the Global Services team focuses on enhancing client security through technical testing and defense strategy knowledge. Responsibilities include performing network, web application, and API penetration tests, social engineering, and producing high-quality reports. The analyst will translate technical findings for non-security personnel, learn in a fast-paced environment, and potentially lead solo engagements. Key skills include 3+ years in a technical security role, knowledge of modern penetration testing tools and methods, network/web/802.11 security concepts, OS internals, and programming languages like Ruby or Python. Experience with social engineering techniques is also required.

As a Penetration Testing Analyst, you will work on the Global Services team to help clients improve their security posture through your technical skills and knowledge of defense strategies. You will enjoy attacking networks and hacking custom protocols implemented in embedded devices.
About The Role
As a Penetration Testing Analyst, your primary responsibility will be to perform technical testing against a variety of targets and to help deliver day-to-day tactical reports to our customers. You will have a front-row seat to observe and learn about the ever-evolving cyber threat landscape and gain valuable experience by helping customers remediate and mitigate prevalent threats.
Specifically, Your Focus Will Be To

  • Perform technical testing against a variety of targets, including network penetration testing (internal, external, and wireless), web application and API testing, and social engineering (on-premise and electronic).
  • Consistently produce high-quality reports and peer-review colleagues' work for errors and inaccuracies.
  • Help develop and create Executive Briefings.
  • Deliver timely reports to clients and external stakeholders.
  • Translate technical concepts and convey them to non-security personnel.
  • Be capable of learning in a fast-paced environment and taking on solo engagements.
  • Participate in industry conferences and professional organizations.

The Skills And Qualities You’ll Bring Include

  • 3+ years in an active technical security role.
  • Previous technical security consulting experience.
  • Knowledge of modern penetration testing tools and methods.
  • Strong knowledge of network, web-based application, and IEEE 802.11 security concepts.
  • Knowledge of Windows/Linux/UNIX internals and the Internet protocol suite.
  • Experience using interpreted languages (Ruby, Python, PHP, etc.) and knowledge of compiled languages (Java, C, C++, Assembly, etc.).
  • Experience with social engineering techniques and tactics.
  • A Bachelor’s degree in Computer Science, MIS, CIS or a related field, or equivalent experience.
  • Certifications such as GPEN, CPTS, or OSCP.
  • The ability to ask for help.
  • Be an Advocate: Use excellent written and verbal communication skills to not just report vulnerabilities, but to advocate for the customer's security posture. Focus on "translating technical concepts" so non-security personnel understand the impact on their business.
  • Strategic Alignment: Position your technical testing (network, web app, API) as a way to scale Rapid7's impact within the Global Services division.
  • Driving Outcomes over Actions: Instead of just listing "performed technical testing," focus on the outcome: "helping customers remediate and mitigate prevalent threats". Your ability to consistently produce high-quality reports is a direct contribution to successful security outcomes for clients.
  • Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.

We know that the best ideas and solutions come from multi-dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope just like we’ ve been doing for the past 20 years. If you ’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.
Rapid7, Inc. is committed to fair and equitable compensation practices. A candidate’s salary is determined by various factors including, but not limited to, relevant work experience, skills, and certifications. We evaluate compensation decisions on a case-by-case basis, and it is not typical for an individual to be hired at the very top of the salary range.
The salary range for this role in the US is:
$89,300.00 - 120,800.00 USD Annual
Salary ranges may vary based on geographical location. This range does not include variable/incentive compensation, equity and benefits (where applicable/eligible).
*All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.*

Ready to apply?
You'll be redirected to Rapid7's application page.

Similar roles