Somos, Inc. · 1 day ago
Senior Penetration Tester
Somos, Inc. is an innovative technology company that ensures that phone calls and text messages can be trusted. They are seeking a highly skilled Senior Penetration Tester to lead offensive security operations, manage vulnerabilities, and oversee application security testing.
Telecommunications
Responsibilities
Lead and execute red team engagements, emulating advanced threat actors to assess detection and response capabilities
Perform internal and external penetration testing across networks, applications, APIs, cloud environments, and physical security (as required)
Develop and manage penetration testing methodologies, tooling, and reporting standards
Provide actionable remediation recommendations to engineering, DevOps, and IT teams
Oversee the end-to-end vulnerability management program, including identification, prioritization, tracking, and remediation validation
Partner with IT and application owners to drive timely patch management, ensuring critical vulnerabilities are addressed within SLA
Continuously refine vulnerability scoring and risk-based prioritization models
Own and maintain the organization’s SAST, DAST, and SCA tooling and processes
Collaborate with development teams to integrate security testing into CI/CD pipelines
Review application architecture, code, and configurations to identify security gaps
Provide secure coding guidance and lead developer training sessions
Assist in internal and external audits, including SOC 2, ISO 27001, PCI, FISMA or other relevant frameworks
Provide evidence, documentation, and subject-matter expertise during audit activities
Support remediation of audit findings and control improvements
Qualification
Required
8 years related experience, including 5+ years of experience in penetration testing, red teaming, or offensive security roles, or an equivalent combination of education and experience
Strong knowledge of network, web application, and cloud security concepts
Security certifications such as CISSP, CISA, OSCP, or CEH
Hands-on experience with penetration testing and red team toolsets (e.g., Burp Suite, Cobalt Strike, Metasploit, Nessus, Kali Linux, BloodHound, etc.)
Experience running and managing SAST, DAST, and SCA tooling (e.g., Veracode, Qualys, GitHub Advanced Security, WIZ, SonarQube)
Strong understanding of vulnerability scoring systems (CVSS), exploitability, and risk management
Familiarity with common security standards (OWASP Top 10, NIST CSF, MITRE ATT&CK)
Ability to clearly communicate technical issues and risk to executives and technical team
Preferred
Experience with cloud platforms (AWS, Azure, GCP)
Background supporting compliance frameworks (SOC 2, ISO 27001, PCI, etc.)
Hands-on experience in secure SDLC and CI/CD toolchains
Proactive, detail-oriented, and self-driven
Strong analytical and problem-solving skills
Ability to work cross-functionally with Engineering, IT, Compliance, and Leadership
Passionate about offensive security, emerging threats, and continuous improvement
Benefits
100% Company Paid Medical, Dental and Vision insurance for you and your family!
401(k) Savings Plan with Employer Contribution
100% Company Paid Short- and Long-Term Disability
100% Company Paid Life Insurance
Flexible Time Off program
A Variety of Voluntary Benefits
Company
Somos, Inc.
In our increasingly digital world, trust is paramount.
H1B Sponsorship
Somos, Inc. has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2024 (2)
2023 (2)
2021 (1)
Funding
Current Stage
Growth StageLeadership Team
Recent News
2025-12-02
Company data provided by crunchbase