Job Description
Are you a person who is passionate about breaking applications, devices, services and/or processes to help protect them against the worlds most advanced cyber security adversaries?
The Information Security Protect organization at Procter & Gamble is responsible for providing a realistic depiction of threat actor behaviors and scenarios during simulated exercises. We drive improvements to applications and systems, as well as detection and response capabilities through regular testing of security controls across the enterprise.
Responsibilities:
- Lead defined-scope penetration tests across assigned areas such as websites, services, APIs, infrastructure, cloud environments, networks, IoT devices, mobile applications, and enterprise applications.
- Partner with Intake Management, senior testers, and stakeholders to confirm objectives, access, rules of engagement, test assumptions, and engagement readiness.
- Execute testing activities including reconnaissance, vulnerability discovery, exploitation, evidence collection, reporting, and remediation validation.
- Identify, validate, exploit, and clearly document security vulnerabilities while operating safely within approved scope.
- Validate related vulnerabilities together where appropriate to demonstrate realistic impact within the boundaries of the engagement, escalating complex attack chains as needed.
- Test for control gaps where relevant and document observed weaknesses in preventative or detective controls.
- Investigate and validate Vulnerability Disclosure Program and Bug Bounty findings, escalating complex or high-impact issues as needed.
- Work with engineering, product, cloud, infrastructure, and security teams to explain findings and support practical remediation.
- Use approved scripts, templates, automation, and AI-assisted workflows to support testing efficiency, triage, reporting, and remediation validation.
- Assist with testing AI-enabled applications and integrations for common risks such as prompt injection, sensitive data exposure, insecure tool use, and authorization flaws.
- Produce clear standardized reports with reproduction steps, evidence, impact, affected systems, and remediation guidance.
- Contribute to team knowledge sharing, documentation, test notes, templates, and process feedback.