Junior Ethical Hacker
Grow your Career with Paylocity!
Delivering one-of-a-kind cloud technology, accompanied by award winning customer service, Paylocity is a software development company in a category of its own. We are a publicly traded company that offers an Employee Stock Purchase Program (ESPP) which enables employees to share in the long-term growth and future success of the company.
Poised to revolutionize the world of human capital management for hundreds of thousands of small and medium sized businesses, we are seeking the best and the brightest to help us create the future of our talent solutions – enabling our customers to better develop their employees and supervisors.
The Junior Ethical Hacker is responsible for verifying that our cloud based Software-as-a-Service (SaaS) web applications are secure. The role involves performing threat modeling, security assessments, and ethical hacking of our web applications. In addition, the Junior Ethical Hacker will be producing reports that document the risk of vulnerabilities identified by security assessments and penetration tests for each product team and our auditors.
Are you the leader we are looking for?
Who you are:
- Passionate about information security and privacy
- An evangelist regarding the importance of information security
- Well versed in security issues affecting financial service organizations as well as widespread data center operations, such as cloud and mobile technology solutions
- Committed to an ongoing partnership with other high profile groups within the organization (e.g. software development) to insure information security objectives are being understood and embraced
- Established presence within information security communities
- Ability to anticipate problems and recommend decisive action
- Excellent communication skills (both written and oral)
- Ability to work collaboratively across the organization
- Self-driven, creative, and resourceful
How we work:
- Casual, collaborative environment which embraces and operates under our shared principles
- Complete transparency with open, honest discussions about our progress
- Close working relationships across all areas of the organization
- Focus on outcomes and learning
What we offer:
- A strong commitment to Information Security both financially and organizationally
- An existing talented and passionate Information Security team
- The chance to meaningfully contribute to a vast market opportunity
- A collaborative environment where our security team is empowered to help steer the direction of the team
- A place to contribute your security knowledge company-wide through forum panels with our product development team
- Annual training allowance to learn new things and bring it back to the team.
- Flexible remote work schedule
- Employee Stock Purchase Program (ESPP) which enables employees to share in the long-term growth and future success of the company
- Preferred education equivalent to a Bachelor’s degree in Computer Science, Information Security or a related discipline
- 0-3 years of experience in software development or web application security testing
- Ability to perform both manual and automated code reviews
- Solid understanding of object oriented programming concepts
- Solid understanding of OWASP and other software security best practices
- Familiarity with security and testing tools such as Burp Suite
- Experience with threat modeling and security design review methodologies
- Experience with penetration testing against a wide variety of application layer platforms, including web, mobile, and thick client above and beyond running automated tools
- Demonstrates excellent organizational and prioritization skills
- Demonstrates excellent reporting skills and test planning preparation skills (including test case creation and execution)
- Experienced meeting corporate security policies and regulatory requirements
- Strong verbal and written skills.
- Strongly prefer a relevant security certification (Certified Information Systems Security Professional/CISSP, GIAC Certifications such as GWAPT or GPEN, and/or Certified Ethical Hacker/CEH)
During the last three months, you would have:
- Evaluated security threats, assess the potential impact to the business, and implement strategies to detect and generate alerts on security incidents
- Performed threat modeling, ethical hacking (both automated and manual), and security assessments on web and mobile applications.
- Worked collaboratively with IT and Software Development to continually improve security posture.
- Calculated risk and created reports that documented our current risk of vulnerabilities identified from penetration tests for a variety of product teams.
- Handled escalations quickly and worked closely with product teams to verify that any identified vulnerabilities are addressed.
- Glassdoor's Employees Choice Award in 2014
- 7-time Winner on Chicago Area's 101 Best and Brightest Companies to Work For
- Inc Magazine listed Paylocity as an Inc 5000 Fastest Growing Privately Held Firm from 2007-2013
- Ranked #14 on Built in Chicago Top 100 Digital Companies for 2014
- Ranked #24 on Forbes 2013 List of Top 100 Digital Companies in Chicago
- Ranked #38 on Crain's Fast Fifty List of Chicago's Fastest Growing Companies in 2014
- Ranked #334 on Deloitte's 2014 Technology Fast 500 List of Fastest Growing Companies in North America
In the spring of 2014, Paylocity officially went public, trading on the NASDAQ under the ticker symbol “PCTY.” We are an eight-time INC. Magazine winner for being one of America’s Fastest Growing Privately-held Companies, as well as a seven-time winner for being one of Chicago’s 101 Best & Brightest Companies to Work For, and four-time winner for being one of the Best Places to Work in Illinois.
At Paylocity, our mission is to elevate the profession of Payroll and Human Resources out of the back office and into the boardroom where it belongs. We do this by providing clients with the same caliber Cloud software solutions found in other critical areas such as Sales, Finance, and Operations.
Some of our most recent awards and accolades include:
Ranked on Forbes list of “Top 100 Digital Companies in Chicago”
Voted by Glassdoor as one of the "Best Medium-Sized Companies to Work" for in 2014
Voted one of the “101 Best & Brightest Companies to Work for in Chicago” in 2014
Voted one of the “Best Places to Work in Illinois” in 2013
Cloud-based Payroll & HR Solutions, Time and Labor Software, Benefit Administration Software
Company Type: Public Company
Company Size: 1,001-5000