×
Register Here to Apply for Jobs or Post Jobs. X

Security Engineer, Penetration Testing

Job in Little Rock, Pulaski County, Arkansas, 72208, USA
Listing for: ISC2
Full Time position
Listed on 2026-06-29
Job specializations:
  • Engineering
    Cybersecurity, Systems Engineer
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 90000 - 115000 USD Yearly USD 90000.00 115000.00 YEAR
Job Description & How to Apply Below

Overview Your Future. Secured. ISC2 is a force for good. As the world’s leading nonprofit member organization for cybersecurity professionals, our core values — Integrity, Advocacy, Commitment, Inclusion, and Excellence — drive everything we do in support of our vision of a safe and secure cyber world. Our globally recognized, award-winning portfolio of certifications provide an independent and globally recognized endorsement of cybersecurity knowledge, skills and experience for all career levels.

Our charitable arm, the Center for Cyber Safety and Education, enables ISC2 and our members to serve the public by educating the most vulnerable about cyber risks and empowering access to enter and thrive in the cyber profession.

Position Summary

The Security Engineer, Penetration Testing is a dual-function role responsible for both executing offensive security assessments and building the defensive engineering controls that harden ISC2’s environment. The role leads authorized penetration testing across ISC2’s applications, networks, and cloud infrastructure while also owning security engineering work — including security architecture review, tooling, automation, and control implementation — that translates findings into lasting improvements.

This position works closely with the Security and Technical Operations team and collaborates across IT, engineering, and product to continuously strengthen ISC2’s security posture. The role plays a critical part in supporting ISC2’s ISO/IEC 27001:2022 ISMS program, providing both evidence of technical control effectiveness and direct input into risk treatment.

Responsibilities Penetration Testing
  • Plan, execute, and document internal and external penetration tests against ISC2 applications, networks, cloud environments, and infrastructure.
  • Perform vulnerability assessments and validate findings to distinguish genuine risks from false positives.
  • Conduct web application, API, mobile, and network vulnerability assessments using industry-standard methodologies (OWASP, PTES, OSSTMM).
  • Perform social engineering assessments, including phishing simulations and physical security testing as authorized.
  • Produce clear, actionable written reports detailing findings, risk ratings, evidence, and remediation recommendations tailored to both technical and executive audiences.
  • Support red team exercises and adversary simulation activities to test detection and response capabilities.
  • Develop and maintain the penetration testing program, including scope definitions, rules of engagement, and testing schedules. Move towards a continuous test mindset and method.
  • Coordinate with third-party security vendors for external assessments and bug bounty program management where applicable.
Security Engineering
  • Own remediation follow-through: translate pen test findings into security engineering work items,validate fixes, and track resolution to closure in Jira Service Management.
  • Design and implement security controls across ISC2’scloud and on-premisesenvironments, including hardening configurations for Azure, Okta, Sentinel One, CheckPoint, and F5 XD.
  • Participate in security architecture and design reviews for new systems, integrations, and third-party products; provide security requirements and risk acceptance recommendations.
  • Develop and maintain security automation scripts and tooling to improve detection coverage, reduce manual effort in assessment workflows, and support continuous monitoring.
  • Support the Secure Software Development Lifecycle (SSDLC), including security requirements definition, code review support, and pre-deployment security validation.
  • Maintain awareness of emerging vulnerabilities, exploits, and threat actor TTPs; operationalize threat intelligence into actionable hardening and detection improvements.
  • Support ISC2’s ISO/IEC 27001:2022 ISMS by providing technical evidence and input for Annex A controls spanning vulnerability management (A.8.8), secure development (A.8.25–A.8.29), and technical review (A.8.29).
  • Miscellaneous duties as assigned.
Behavioral Competencies
  • Integrity & Ethics:
    Operates with the highest standard of professional ethics; treats privileged access, sensitive…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary