Job Description A global professional services organization is seeking a
Vulnerability Assessment & Penetration Testing (VAPT) Engineer to join its cybersecurity team in
Chicago, IL. This individual will play a critical role in evaluating and improving the security posture of enterprise systems, applications, and infrastructure through comprehensive vulnerability assessments and penetration testing activities.
This position is geared toward a seasoned offensive security professional who can operate as a subject matter expert, lead testing initiatives, and provide actionable guidance to technical and non-technical stakeholders. The ideal candidate combines deep technical expertise with strong communication skills and a practical approach to risk management.
The organization is committed to maintaining a mature security program and is looking for someone who is passionate about identifying weaknesses, validating risks, and helping drive security improvements across a complex enterprise environment. Required Skills & Experience
- 7+ years of cybersecurity experience with significant hands-on penetration testing and vulnerability assessment expertise
- Strong understanding of vulnerability assessment and penetration testing methodologies, scope, objectives, and reporting requirements
- Experience conducting web application, network, infrastructure, and mobile security assessments
- Advanced proficiency with tools such as Nessus, Burp Suite, AppScan, Nipper, and similar assessment platforms
- Expertise utilizing offensive security frameworks and tools including Kali Linux, Metasploit, Wireshark, and related technologies
- In-depth knowledge of OWASP Top 10, CVE frameworks, security controls, and current exploitation techniques
- Ability to manually verify vulnerabilities and eliminate false positives
- Experience creating detailed technical reports and executive-level remediation recommendations
- Strong written and verbal communication skills
- Ability to work independently while managing multiple assessments and priorities
- CISSP certification required
- OSCP certification required
- Bachelor's degree in Computer Science or equivalent professional experience
Desired Skills & Experience
- GPEN, GWAPT, or other GIAC offensive security certifications
- Experience with API security testing and assessment methodologies
- Proficiency in scripting or programming languages used for security testing and automation
- Experience assessing AI-enabled applications, agents, and emerging technologies
- Familiarity with secure development practices and application security concepts
- Experience developing security awareness, training materials, or technical documentation
What You Will Be Doing
Daily Responsibilities - Lead vulnerability assessments and penetration testing engagements across enterprise systems and applications
- Serve as the primary technical advisor and subject matter expert for offensive security initiatives
- Manage and optimize core VAPT tools, technologies, and processes
- Conduct web, mobile, API, network, and infrastructure security assessments
- Validate vulnerabilities through manual testing and exploitation techniques
- Document findings and deliver clear, risk-based recommendations to stakeholders
- Collaborate with security, infrastructure, and application teams to support remediation efforts
- Monitor emerging threats, attack techniques, and industry best practices
- Contribute to the ongoing improvement of vulnerability management and testing programs
- Assist in the creation of internal security documentation, standards, and training content
The Offer
- Hybrid opportunity in Chicago, IL
- Base salary up to $145,000
- Opportunity to work on complex enterprise security initiatives
- High visibility role with significant ownership and impact
- Collaborative and security-focused team environment
You will receive the following benefits
- Medical Insurance
- Dental Benefits
- Vision Benefits
- Paid Time Off (PTO)
- 401(k)
Applicants must be currently authorized to work in the US on a full-time basis now and in the future.