Security Engineer, Penetration Testing & Vendor Security

Posted 3 days ago

gambit technologiesBrooklyn (NY)

SENIORITY

Senior

Apply

About the role

Security Engineer, Penetration Testing & Vendor Security Manhattan, hybrid. NYC metro only. This one is for people who test things. If you've installed an app and gone looking for what an attacker would find, this role may be for you. My client is one of the largest private philanthropies in the country, based in Manhattan. The money funds public health, climate, education, government innovation, and the arts, and it moves fast. The security team is small. You report to the CISO directly, you know everyone on the team, and when you tell leadership a tool isn't safe to buy, that's usually where the conversation ends. Here's what a week looks like. HR wants a new platform that holds employee data. You pull the vendor's SOC 2 and notice the observation window is three months and the scope skips the system that would actually hold the data. Then you spin the tool up and test it yourself, because \"we enforce MFA\" is a sentence until somebody tries to get around it. You write it up in plain English for HR and Legal, and you're in the room when they decide. Next week it's a CVE that just dropped. You figure out whether it's actually reachable in this environment or just a scary number. After that maybe it's scoping an outside red team, or tuning DLP rules so they stop firing on every spreadsheet. You get both halves: the testing, and a real say in what happens with the results. That combination is hard to find. What they need: Hands-on testing. Burp, Kali, Nmap, manual app and auth testing. The judgment to tell what vendor evidence is actually worth.5+ years in security with real keyboard time. What they'll teach you: Their tech stack. Splunk, Crowd Strike, Netskope, Qualys, and a few others. OSCP, GPEN, or GWAPT is a strong signal. People from pentest consultancies or small in-house teams tend to fit well.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this