Senior Analyst - Cybersecurity (Penetration Tester)

Reposted 18 Days Ago
Be an Early Applicant
Hiring Remotely in Poland
Remote
Senior level
Food • Logistics
The Role
The Senior Penetration Tester leads testing of web applications, APIs, cloud services, and internal environments, addressing vulnerabilities and collaborating with security teams.
Summary Generated by Built In
JOB DESCRIPTION

Job Title:  Senior Analyst - Cybersecurity (Penetration Tester)

Location: Hybrid (2 days in the office)

Type: Full Time

Role overview

We are looking for a Senior Penetration Tester to lead testing across web applications, APIs, cloud services (Azure, AWS, GCP) and internal environments. You’ll work closely with AppSec, cloud, vulnerability, and threat hunting teams, using Veracode and Burp as core tools and following up with deep manual testing. The role includes occasional planned evening and weekend work for production testing, with comp days so your week still averages ~40 hours / 5 days.

Key responsibilities

  • Lead penetration tests for web and API applications, including modern JavaScript apps, WordPress and Apache-based services.
  • Use Veracode SAST/DAST and Burp Suite to identify issues, then perform manual testing to uncover logic, authorization, and high-impact vulnerabilities.
  • Test Azure, AWS and GCP environments using tools like ScoutSuite, Prowler, Pacu (or similar) to find misconfigurations and escalation paths.
  • Assess Active Directory and Azure AD using BloodHound (and similar tools) to identify and validate attack paths.
  • Perform security testing of AI/ML/LLM-backed features and integrations to identify data leakage, unsafe integrations and abuse paths.
  • Manually retest vulnerabilities—primarily on the external attack surface, with some internal scope—to confirm that remediation is effective.
  • Work with threat hunters and detection engineers to simulate attacks and validate that new or updated detections behave as intended and don’t create excessive noise.
  • Produce clear reports and explain technical findings, impact and remediation options to both technical and non-technical stakeholders.
  • Participate in planned evening and weekend testing windows, with weekdays off in exchange so total time stays within normal full-time hours.

Required experience & skills

  • 5+ years of hands-on penetration testing or offensive security experience, including leading complex engagements.
  • Strong experience in web and API testing, including OWASP-style issues and business logic/authorization flaws.
  • Practical experience with Veracode (or a similar SAST/DAST platform) and advanced use of Burp Suite.
  • Experience testing all three major clouds: Azure, AWS, and GCP.
  • Hands-on assessment of AD/Azure AD using BloodHound or comparable tooling.
  • Experience testing AI/ML/LLM-backed systems or AI-enabled features from a security perspective.
  • Comfortable with planned off-hours work (evenings/weekends) when required, with comp days to keep workload reasonable.
  • Strong written and verbal communication skills in English.

Preferred qualifications

  • Mobile app testing experience (e.g., MobSF, Frida).
  • Familiarity with additional AD tools (e.g., PingCastle).
  • Experience building custom scripts, PoCs, or exploits (Python, PowerShell, Bash, etc.) to exercise vulnerabilities and test controls.
  • Certifications such as OSCP, GPEN, GXPN, CEH or similar.

Working in our international team

  • Lead and participate in engagements with stakeholders across multiple regions.
  • Heavy use of written communication (tickets, docs, reports).
  • Contribute to an environment that encourages sharing research, tooling, and lessons.
  • Close collaboration with Vulnerability and Threat Hunting teams.

Skills Required

  • 5+ years of hands-on penetration testing or offensive security experience
  • Strong experience in web and API testing
  • Practical experience with Veracode and Burp Suite
  • Experience testing Azure, AWS, and GCP
  • Hands-on assessment of AD/Azure AD using BloodHound
  • Experience testing AI/ML/LLM-backed systems
  • Strong written and verbal communication skills

Sysco Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sysco and has not been reviewed or approved by Sysco.

  • Healthcare Strength Multiple national medical plan options with telehealth, behavioral health resources, and targeted programs indicate broad coverage and support. Preventive care access and ancillary offerings (dental, vision, Rx advocacy) further reinforce the package.
  • Retirement Support A 401(k) with automatic company contributions plus a match, alongside an employee stock purchase plan, underscores solid retirement support. At union locations, enhanced pension terms add to perceived long‑term value.
  • Pay Growth & Progression Recent collective bargaining outcomes with substantial wage increases demonstrate meaningful pay progression where contracts apply. In high‑volume markets, incentive structures can amplify earnings beyond base rates.

Sysco Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Houston, TX
24,120 Employees

What We Do

Sysco is the global leader in selling, marketing and distributing food and related products to customers who prepare meals away from home. This includes restaurants, healthcare and educational facilities, lodging establishments, entertainment venues, and more. Sysco operates almost 340 distribution centers, in over 10 countries, with 76,000 colleagues serving approximately 730,000 customer locations. The company generated sales of more than $81 billion in fiscal year 2025 that ended June 28, 2025. As the world’s largest food-away-from-home distributor, Sysco offers customized supply chain solutions, bespoke specialty product offerings, and culinary support to drive customers to innovate and optimize their operations. We act as a trusted business partner to our customers, helping them grow through our industry-leading portfolio that includes fresh produce, premium proteins, specialty products, sustainably focused items, equipment and supplies, and innovative culinary solutions. For more information, visit www.sysco.com. For important news and key information for Sysco investors, visit the Investor Relations section of the company’s website at investors.sysco.com.

Similar Jobs

Capco Logo Capco

Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Motorola Solutions Logo Motorola Solutions

Manager Technical Training Silvus

Artificial Intelligence • Hardware • Information Technology • Security • Software • Cybersecurity • Big Data Analytics
Remote or Hybrid
Poland
23000 Employees

Circle (circle.so) Logo Circle (circle.so)

Lead Product Designer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Easy Apply
Remote
31 Locations
250 Employees
140K-170K Annually

DuckDuckGo Logo DuckDuckGo

Director, User Insights

Information Technology
Remote
14 Locations
393 Employees
244K-244K Annually

Similar Companies Hiring

HERE Technologies Thumbnail
Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Amsterdam, NL
6000 Employees
Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
22 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account