Penetration Test Engineer Job at Kia America, Irvine, CA

V05qMXpmVmFGdkZGbDNjTUtPcnRvZ21JU2c9PQ==
  • Kia America
  • Irvine, CA

Job Description

At Kia, were creating award-winning products and redefining what value means in the automotive industry. It takes a special group of individuals to do what we do, and we do it together. Our culture is fast-paced, collaborative, and innovative. Our people thrive on thinking differently and challenging the status quo. We are creating something special here, a culture of learning and opportunity, where you can help Kia achieve big things and most importantly, feel passionate and connected to your work every day. Kia provides team members with competitive benefits including premium paid medical, dental and vision coverage for you and your dependents, 401(k) plan matching of 100% up to 6% of the salary deferral, and paid time off. Kia also offers company lease and purchase programs, company-wide holiday shutdown, paid volunteer hours, and premium lifestyle amenities at our corporate campus in Irvine, California. Summary Under the direction of Information Security management, the Penetration Test Engineer is responsible for protecting Kia America (KUS) including subsidiaries from cyberattacks which can result in loss of sensitive data, harm to the company brand or disruption to business operations. This position will report to the Manager, Information Security and be a key member of the Information Security team. This critical role will coordinate the information security reviews of company IT initiatives either directly or through IT service providers. This includes conducting security risk assessments, performing penetration tests, identifying threats and vulnerabilities, and presenting recommendations to address them. The Penetration Test Engineer will take necessary actions and preventive measures, such as analyzing security system logs, to protect company information systems, including employee, dealer and consumer facing systems, from being compromised. This role will investigate the security vulnerabilities of company information systems and provide solutions and methods to remediate them. This role is also responsible for creating, updating, and testing the companys incident response procedures for handling security events. This includes conducting regular table-top exercises to continuously improve the effectiveness of these procedures and minimize the recovery time and business impact of an actual security event. This role will work with internal and external parties to conduct forensic analysis to determine root causes and implement corrective and preventive plans. The Penetration Test Engineer works closely with KUS business units and security service providers to develop optimal solutions for short-term and long-term enhancements of KUSs security maturity. Major Responsibilities 1st Priority - 70% Conduct penetration tests against Kia Americas corporate web/business applications, servers, APIs, mobile apps, networks, cloud environments and connected cars. Create detailed technical reports describing discovered vulnerabilities, approach taken to identify them, method to duplicate findings, vulnerability risk level and recommendations to mitigate the risks. Oversee, or perform, all penetration test phases (Reconnaissance, Scanning, Vulnerability Assessment, Exploitation, Remediation and Reporting). Stay current on new and emerging security threats and the security tools and methods necessary to mitigate them. 2nd Priority - 30% Establish security incident response policies and procedures and conduct regular training. Conduct table-top exercises to verify incident response procedures and documentation are effective. In the event of a security event, lead the efforts to analyze logs and investigate details of the event to take appropriate actions. Education/Certification Bachelors degree or comparative experience with emphasis on information security. Advanced degree and/or certification(s) in cyber security a plus. Overall Experience 8+ years of experience in an organization with mature security practices. 3+ years of experience in conducting hands-on security penetration tests and vulnerability management. Experience working on Red Teams to identify vulnerabilities with Internet facing business systems is preferred. 3+ years of experience within information security incident response, cybersecurity, and/or IT risk management. Experience with conducting penetration testing on vehicles a plus. Substantial experience, and successes, in CTF competitions and/or bug bounty programs. Familiar with security related regulations and compliance requirements. Familiar with the information security auditing process and evidence collection. Other: Must be proactive, self-motivated, and lead team to multiple concurrent solutions. Skills Skilled in leading cross-functional teams in responding to security events. Deep knowledge of IT and security infrastructure (Networks, Server HW & SW, Security Components (FW, IPS, IDS, EDS, etc.). Skilled with automation and scripting (Python). Advanced level of expertise with penetration testing tools (Burp Suite, Kali Linux, Metasploit, John the Ripper, Nmap, Wireshark, OWASP ZAP, Aircrack-ng, Tenable Nessus, and others). Skilled in identifying application vulnerabilities (OWASP) and advising application teams on how to remediate them. Ability to manage external vendors in the development and delivery of related products, programs, and services. Excellent customer service ability and strong verbal and written communication skills. Expert level knowledge and understanding of the attack chain, adversary tactics, techniques, and procedures, emerging threats and vulnerabilities. Expert level knowledge of SIEMs, how they work, how their value can be maximized and leveraged to mature monitoring and detection processes. Requires high-level organizational, planning, analytical, and technical skills. Pay Range $125,000 - $150,000 Pay will be based on several variables that are unique to each candidate, including but not limited to, job-related skills, experience, relevant education or training, etc. #J-18808-Ljbffr Kia America

Job Tags

Temporary work,

Similar Jobs

Chef Robotics™, Inc.

Senior Robotics Software Engineer, Manipulation Job at Chef Robotics™, Inc.

About Our TeamChef Robotics is on a mission to accelerate the advent of intelligent machines in the physical world. As the rise of LLMs...  ...have a great team, where you will be surrounded by talented engineers and tech leaders from companies like Cruise, Zoox, Google,... 

HARRISON GREEN

Landscape Designer/Architect Job at HARRISON GREEN

TITLE: HARRISON GREEN Landscape Designer/Architect SALARY: Salary, Benefits $70,000$90,000 commensurate with experience WORK LOCATION: New York City Overview: HARRISON GREEN is seeking dynamic design professionals to join our award-winning Landscape ...

CHRISTUS Health

Certified Nursing Assistant-Nursing Float Pool-PRN Job at CHRISTUS Health

Description Summary: Under the direct supervision of a Registered Nurse/licensed Nurse, this position will assist with routine and repetitive patient care activities in a nursing unit. This position also performs specific clerical, organizational, and patient-focused activities...

Mapcore

Concept Artist - Crystal Dynamics - Redwood City, CA Job at Mapcore

Concept Artist - Crystal Dynamics - Redwood City, CA! Reports to: Creative Director and Art DirectorManaged by: Art DirectorTitle DescriptionThe Concept Artist is responsible for working with the Creative Director and Art Director on the visual development of existing... 

Pactiv Evergreen - North America

Print Operator Job at Pactiv Evergreen - North America

**PRINT OPERATOR **|Mooresville, NC | **HIRING IMMEDIATELY****Available Shift**: 6:30PM-6:30AM NIGHTS Responsibilities The primary responsibility of the Printing Operator position is for the safe setup and operation of all phases of the printing operation. This...