Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Senior Application Security Penetration Tester (Remote) image - Rise Careers
Job details

Senior Application Security Penetration Tester (Remote) - job 4 of 4

Company Description

AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas – immunology, oncology, neuroscience, and eye care – and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com. Follow @abbvie on XFacebookInstagramYouTubeLinkedIn and Tik Tok.

Job Description

AbbVie Information Security is looking for a highly motivated, diligent, and skillful analyst to join the Attack Surface Management (ASM) team. AbbVie’s Application Security team protects AbbVie’s patients, data, and brand by identifying vulnerabilities and threats to our organization and working to drive remediation of identified security risks. Application Security is a capability of ASM within the larger Cyber Security Operations (CSO) function. Join us as Senior Security Specialist, Application Security to support and improve our efforts to identify and reduce AbbVie’s attack surface and help our business continue to have remarkable impacts on people’s lives.

This position can be based virtually anywhere in the U.S.

The Senior Security Specialist is a key member of the Application Security team and works with internal and external groups to identify and drive remediation of information security risks across all AbbVie application environments.

The ideal candidate must have prior experience leading manual web and mobile application security penetration tests within an enterprise environment and working with application stakeholders to discuss vulnerabilities and remediation options.

Responsibilities

  • Maintaining awareness of the latest critical information security vulnerabilities, threats, and exploits
  • Support the enterprise-wide initiative to secure AbbVie’s most critical assets by performing thorough assessments of web and mobile applications and working with key stakeholders to drive remediation of identified risks.
  • Providing guidance on existing and emerging threats in the web and mobile application space, as they apply within the AbbVie environment
  • Performing application security reviews throughout the application development lifecycle, including tasks such as:
    • Performing security assessments for AbbVie web and mobile applications across the enterprise
    • Dynamic (DAST) application security testing and/or penetration testing of applications and source code
    • Auditing results of security assessments with development and/or security teams and offering plans for remediation of vulnerabilities
    • Retesting remediation of identified vulnerabilities to confirm the efficacy of fixes
  • Reviewing deliverables from third-party service providers and other Application Security Analysts to ensure completeness and accuracy
  • Communicating technical application security concepts to customers, including developers, architects, and managers
  • Participating in the management of AbbVie’s bug bounty program, working to validate and triage reported vulnerabilities and working with application owners to ensure valid findings are remediated
  • Training customer staff on application security and remediation of application security code defects
  • Identifying and developing secure software development best practices
  • Identifying enhancements to tools, standards and processes; provide input into policies and procedures, and contribute to the implementation and refinement of the strategy for the Application Risk program on a global basis

Qualifications

  • Bachelors Degree and 6 years experience OR Masters Degree and 5 years experience OR PhD and 0 years experience
  • Advanced knowledge of web application vulnerabilities and web application business logic flaws and threats
  • Advanced understanding of application architectures and technologies, including web applications, mobile technology, data encryption, and identity and access management
  • Advanced, hands-on experience with manual vulnerability testing and static code analysis
  • Advanced experience with tools including, but not limited to, the Kali Linux platform and its built-in tools
  • Advanced experience performing manual testing with Burp Suite, OWASP ZAP, or similar tools
  • Advanced understanding of security controls such as Authentication, Authorization, Access Control, Cryptography, and Network Protocols along with security standards: OWASP Top 10, SANS 25, NIST, and CVE
  •  Written and verbal communication skills are critical
  • Communicating concepts to diverse audiences with varying skill sets.
  • Certifications such as OSCP, OSWE or ECSA are a plus

Additional Information

Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: ​​

​​

  • The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future.​​

  • We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.​​

  • This job is eligible to participate in our short-term incentive programs. ​​

​​

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company’s sole and absolute discretion, consistent with applicable law. 

AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community.  Equal Opportunity Employer/Veterans/Disabled. 

US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html

US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:

https://www.abbvie.com/join-us/reasonable-accommodations.html

AbbVie Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
AbbVie DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of AbbVie
AbbVie CEO photo
Richard A. Gonzalez
Approve of CEO

Average salary estimate

$130000 / YEARLY (est.)
min
max
$120000K
$140000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User

Join AbbVie as an Allergan Practice Consultant to leverage your expertise in the aesthetic health care environment and enhance business strategies for key accounts.

Photo of the Rise User

We are seeking an experienced Associate Director to lead Marketing Operations Review Management at AbbVie in Mettawa, Illinois.

Join Significance as a Senior Network Administrator, where your expertise will enhance network operations for federal clients.

Photo of the Rise User
Continental Remote Strada Rudolf Otto, Timișoara, Romania
Posted 8 days ago

As an IT Consultant for QM Applications at OESL, you will play a pivotal role in enhancing quality management systems through technology.

Photo of the Rise User
Posted 14 days ago

As a Cloud Operations Manager at Edmentum, you will lead a dedicated team to optimize and secure cloud operations while fostering innovation.

Posted 3 days ago

Join Talworx as an Application Support Engineer, driving backend development for a premier fintech digital invoice platform.

Posted 3 days ago

Join Northrop Grumman as a Sr Principal Cyber Architect to lead cybersecurity efforts for critical defense communications systems.

Photo of the Rise User

Seeking an IT Support Specialist / Cabling Technician to deliver exceptional support and technical expertise in a dynamic healthcare environment.

Photo of the Rise User

Join Truist Financial Corporation as a Vulnerability Management Technical Manager to enhance their security configuration management initiatives while leading a dedicated team.

Photo of the Rise User
FactSet Remote Philippines, Manila, One Le Grand Tower (Manila - One Le Grand)
Posted 4 days ago

Join FactSet as a Technical Specialist and contribute to optimizing workflows for investment professionals globally.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Rapid Growth
Passion for Exploration
Dare to be Different
Dental Insurance
Life insurance
Health Savings Account (HSA)
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Mental Health Resources
401K Matching
Paid Time-Off
Snacks

AbbVie’s mission is to discover and deliver innovative medicines that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people’s lives across several key therapeutic areas: i...

2994 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 22, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!