Security Engineer II- Penetration Testing

| Chicago, IL, USA
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

About The Opportunity
We're all about connecting hungry diners with our network of over 300,000 restaurants nationwide. Innovative technology, user-friendly platforms and streamlined delivery capabilities set us apart and make us an industry leader in the world of online food ordering. When you join our team, you become part of a community that works together to innovate, solve problems, grow, work hard and have a ton of fun in the process!
Why Work For Us
Grubhub is a place where authentically fun culture meets innovation and teamwork. We believe in empowering people and opening doors for new opportunities. If you're looking for a place that values strong relationships, embraces diverse ideas-all while having fun together-Grubhub is the place for you!
Grubhub's Product Security organization is looking for a Penetration Tester to help build our Offensive Testing & Adversary Emulation capabilities. Your primary task will be to conduct offensive pen-testing activities against our microservices, applications, infrastructure and data-layer systems. You will work closely with our engineering groups to define pen-test scope, lead assessment engagements, and map assessment findings into engineering plans of action for remediation, ultimately guiding our product security uplift activities. This is a unique opportunity for an experienced offensive pen-tester who is collaborative, and has a healthy sense of curiosity to join Grubhub Security to make real positive impacts to our security posture, and help us improve our security designs so that we can deliver trustworthy experiences across the entire Grubhub ecosystem.
This role is based in Chicago, IL and is required 2 days per week in the office.
The Impact You Will Make:

  • You will enhance the overall security posture of Grubhub by identifying and mitigating security vulnerabilities proactively.
  • Streamline security testing processes by automating penetration tests as part of the CI/CD pipeline, reducing manual effort and improving engineering operational excellence.
  • Contribute to a culture of cybersecurity awareness and continuous improvement within the organization, enabling Grubhub to launch and sustain key business initiatives with minimal risk.


Key Responsibilities:

  • Conduct white-box and gray-box offensive penetration testing against Grubhub's mobile applications, front-end & back-end microservices and web services
  • Conduct network infrastructure, Public Cloud (AWS, GCP and Azure), and data-layer offensive pen-testing in support of annual PCI-DSS requirements
  • Perform security assessments on mobile application products and services.
  • Perform manual source code reviews and audits (manual and SCA/SAST code audits) as needed
  • Be a subject matter expert and ambassador to Grubhub Engineering for secure coding practices, penetration testing, mobile platform security and all aspects of application and product security
  • Perform any other application security or product security related activities or tasks as needed or directed
  • Validate 3rd party external pen-test and crowd-sourced application security findings and work with our Appsec team to triage those across to our engineering teams


What You Bring To The Table:

  • Bachelors degree in Computer Science, Information Technology, or related field (or equivalent experience).
  • 3+ years of relevant engineering or security assessment experience
  • Proven experience in manual penetration testing, including web applications, APIs, micro-services, networks, and cloud environments.
  • A broad knowledge of attack vectors, exploits and mitigations that work at scale or may be linked together for chained attacks
  • Intermediate-level experience with Java, Go, or Python with demonstrable experience in conducting code reviews to identify security deficiencies at the code-level.
  • Ability to create and write scripts to automate redundant activities
  • Familiarity with security testing tools such as Burp Suite, Nmap, etc.
  • Strong understanding of CI/CD pipelines and experience with integrating security testing into automated build processes.
  • Knowledge of security controls (like EDR) evasion techniques and ability to apply that knowledge as part of an advanced security assessment.
  • Working familiarity with version control systems (Git) and issue tracking tools (Jira) and ability to define + support your commitments within an Agile working model.
  • Ability to create written work product, detailed technical findings documents, and pen-test reports.
  • Great interpersonal skills, deep technical ability, and a history of successful execution in the assessments industry.
  • Excellent communication skills and ability to work collaboratively in a team environment.
  • Ability to fully participate in our on-call rotation as a service owner


Preferred Qualifications:

  • A pen-test certification such as Offensive Security Certified Professional (OSCP), OSWE, OSCE, GPEN, GMOB, GWAPT, GXPN, eWAPT, eMAPT and/or willing to work towards ultimately obtaining one within the first year as part of your career path


And Of Course, Perks!

  • Flexible PTO. Grubhub employees enjoy a generous amount of time to recharge.
  • Health and Wellness. Excellent medical, dental and vision benefits, 401k matching, employee network groups and paid parental leave are just a few of our programs to support your overall well-being.
  • Compensation. You'll receive a highly-competitive compensation package with eligibility for generous incentives, bonuses, commission, and RSUs.
  • Free Meals. Our employees get a weekly Grubhub credit to enjoy and support local restaurants.
  • Social Impact. We believe in giving back through programs like the Grubhub Community Relief Fund, and provide our employees opportunities to support causes that are important to them.


Grubhub is an equal opportunity employer. We welcome diversity and encourage a workplace that is just as diverse as the customers we serve. We evaluate qualified applicants without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics. If you're applying for a job in the U.S. and need a reasonable accommodation for any part of the employment process, please send an email to [email protected] and let us know the nature of your request and contact information. Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this email address.
If you are a resident of the State of California and would like a copy of our CA privacy notice, please email [email protected].

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
    • JavaLanguages
    • JavascriptLanguages
    • RubyLanguages
    • ReactLibraries
    • ReduxLibraries
    • Ruby on RailsFrameworks
    • SpringFrameworks
    • Google AnalyticsAnalytics
    • SQLAnalytics
    • AxureDesign
    • IllustratorDesign
    • SketchDesign
    • FigmaDesign
    • JIRAManagement
    • SalesforceCRM

Location

111 W. Washington St., Chicago, IL 60602

What are Grubhub Perks + Benefits

Grubhub Benefits Overview

PTO. Grubhub employees enjoy a generous amount of time to recharge.

Health and Wellness. Excellent medical benefits, employee network groups and paid parental leave are just a few of our programs to support your overall well-being.

Competitive Pay. You’ll receive a competitive base salary with eligibility for generous incentives, bonuses, commission or RSUs (role-specific).

Learning and Career Growth. Your personal and professional development is a priority at Grubhub. We empower you to be a leader and grow your career through training, coaching and mentorship opportunities.

MealPerks. Get meals on us! Our employees get a weekly Grubhub credit to enjoy and support local restaurants.

Fun. Every Grubhub office has an employee-led Culture Crew that connects people through fun, meaningful events and initiatives like Wellness Wednesdays, Slack competitions and happy hours!

Social Impact. At Grubhub we believe in giving back. In 2021, the Grubhub Community Fund gave more than $25 million to over 23 charitable organizations.. Employees are also given paid time off each year to support the causes that are important to them.

Half Day Fridays! Grubhub has newly instituted half day Fridays where all employees are encouraged to end their Friday's at 1:00pm local time to get a head start to the weekend! Depending on certain business needs, some teams may implement a different schedule for this time off, but everyone gets to enjoy the perk!

Culture
Volunteer in local community
Partners with nonprofits
Grubhub partners with many Non Profits through our “Donate the Change” program. Past examples include The National LGBT Chamber of Commerce (NGLCC), Feed the Soul Foundation, and World Central Kit
Open door policy
Pair programming
Open office floor plan
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Highly diverse management team
Mandated unconscious bias training
Diversity manifesto
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Team workouts
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
Certain roles within Grubhub are eligible to receive company equity.
Performance bonus
Certain roles within Grubhub are eligible for bonuses.
Charitable contribution matching
Child Care & Parental Leave
Childcare benefits
Generous parental leave
Family medical leave
Return-to-work program post parental leave
Vacation + Time Off
Unlimited vacation policy
Generous PTO
Paid volunteer time
Paid holidays
Paid sick days
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Relocation assistance
Home-office stipend for remote employees
Onsite gym
Professional Development
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education stipend
Technology employees are eligible to receive up to $2,000 annually for continuing education opportunities such as conferences, bootcamps and events.
Continuing education available during work hours
Online course subscriptions available

More Jobs at Grubhub

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about GrubhubFind similar jobs like this