Jobs Companies Sysco Lead Analyst - Penetration Tester

À propos de ce poste Lead Analyst - Penetration Tester chez Sysco

Sysco · Hybride · Sysco LABS - Sri Lanka

JOB DESCRIPTION

Lead Analyst - Penetration Tester 

The Big Picture 

Sysco LABS is the Global In-House Center of Sysco Corporation (NYSE: SYY), the world’s largest foodservice company. Sysco ranks 56th in the Fortune 500 list and is the global leader in the trillion-dollar foodservice industry.  

Sysco employs over 75,000 associates, has 337 smart distribution facilities worldwide and over 14,000 IoT-enabled trucks serving 730,000 customer locations. For fiscal year 2025 that ended June 29, 2025, the company generated sales of more than $81.4 billion. Sysco LABS Sri Lanka delivers the technology that powers Sysco’s end-to-end operations.  

Sysco LABS’ enterprise technology is present in the end-to-end foodservice journey, enabling the sourcing of food products, merchandising, storage and warehouse operations, order placement and pricing algorithms, the delivery of food and supplies to Sysco’s global network and the in-restaurant dining experience of the end-customer.  

 

The Opportunity 

The Lead Analyst - Penetration Tester is a key role within Sysco’s Corporate Cybersecurity organization, responsible for leading offensive security testing across web applications, APIs, cloud platforms (Azure, AWS, GCP), and internal enterprise environments. 

This is a senior individual contributor role suited for an experienced penetration tester who enjoys deep manual testing, uncovering complex attack paths, and partnering closely with Application Security, Cloud Security, Vulnerability Management, and Threat Hunting teams. The role includes planned evening or weekend testing for production environments, balanced with compensatory time off to maintain a sustainable work schedule. 

 

Responsibilities: 

  • Leading penetration testing of web and API applications, including JavaScript-heavy applications, WordPress, and Apache-backed services, using Veracode, Burp Suite, and advanced manual testing techniques 

  • Conducting penetration testing and security assessments of cloud platforms (Azure, AWS, GCP) and internal infrastructure, including Active Directory, Azure AD, and identity systems 

  • Assessing modern technologies such as AI/ML and LLM-backed components to identify misuse, data exposure, and abuse scenarios 

  • Producing clear, structured penetration testing reports, communicate risk and remediation priorities, and supporting secure SDLC activities including design and code reviews 

  • Manually retesting vulnerabilities to validate remediation and collaborating with threat hunters and detection engineers to validate detections based on real-world attack paths 

  • Planning and scoping penetration testing engagements, including effort estimation and coordination of off-hours testing windows in alignment with change and maintenance schedules 

  • Maintaining and improving penetration testing standards, tools, checklists, and playbooks across application, cloud, identity, and AI testing domains 

  • Providing technical mentoring and guidance to junior and mid-level penetration testers 

 

Requirements: 

  • A Bachelor’s Degree in Cybersecurity, Computer Science, or a related field 

  • 5+ years of hands-on penetration testing or offensive security experience, including leading complex engagements 

  • Strong expertise in web and API penetration testing, including authentication/authorization flaws, business logic issues, IDOR, SSRF, and injection vulnerabilities 

  • Experience performing cloud security assessments across Azure, AWS, and GCP, identifying misconfigurations and privilege escalation paths 

  • Hands-on experience assessing Active Directory and Azure AD environments using tools such as BloodHound 

  • Must possess the ability to develop scripts, proof-of-concept exploits, and small tools using languages such as Python, PowerShell, or Bash 

  • Strong written and verbal communication skills, with the ability to clearly present findings to technical and non-technical stakeholders 

 

Preferred Qualifications: 

  • A Master’s Degree in Cybersecurity, Computer Science, or a related field 

  • 7+ years of offensive security or penetration testing experience 

  • Certifications such as OSCP, GPEN, GXPN, CEH, eCPPT, eWAPT, CPENT or equivalent 

  • Familiarity with secure SDLC practices and contributing to security standards and playbooks 

  • Experience testing AI/ML-enabled systems and identifying AI-specific abuse cases 

 

Work Mode & Environment 

  • Work Mode: Hybrid 

  • Planned participation in evening or weekend testing windows, with compensatory weekdays off 

  • Minimal travel required 

  • Office-type remote work environment as part of a globally distributed security team 

 

Benefits:   

  • US dollar-linked compensation   

  • Performance-based annual bonus   

  • Performance rewards and recognition   

  • Agile Benefits - special allowances for Health, Wellness & Academic purposes   

  • Paid birthday leave   

  • Team engagement allowance   

  • Comprehensive Health & Life Insurance Cover - extendable to parents and in-laws   

  • Overseas travel opportunities and exposure to client environments   

  • Hybrid work arrangement   

 

Sysco LABS is an Equal Opportunity Employer.  

Prêt à postuler chez Sysco ?
Postuler chez Sysco

À propos de Sysco

Sysco is the global leader in selling, marketing and distributing food products to restaurants, healthcare and educational facilities, lodging establishments and other customers who prepare meals away from home. Its family of products also includes equipment and supplies for the foodservice and hospitality industries. With more than 71,000 colleagues, the company operates 333 distribution facilities worldwide and serves approximately 700,000 customer locations. For fiscal year 2022 that ended July 2, 2022, the company generated sales of more than $68 billion. Information about our Sustainability program, including Sysco’s 2022 Sustainability Report and 2022 Diversity, Equity & Inclusion Repo

Voir tous les emplois chez Sysco →

Emplois similaires

EMW, Inc.
C004912 Penetration Tester (NS) - THU 16 Sep RELAUNCH UPDATE
EMW, Inc.
⚡ Postuler tôt The Hague, South Holland, Neth... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 12 h
Roblox
Senior Offensive Security Engineer
Roblox
⚡ Postuler tôt San Mateo, CA, United States Sur site $196,750–$243,290
● Nouveau 👁 Vu ✓ Postulé il y a 20 h
Samsara
Staff Offensive Security Engineer
Samsara
⚡ Postuler tôt Remote - UK Hybride £138,800–£173,500
● Nouveau 👁 Vu ✓ Postulé il y a 2 j
Samsara
Staff Offensive Security Engineer
Samsara
⚡ Postuler tôt Remote - US Hybride $165,200–$265,500
● Nouveau 👁 Vu ✓ Postulé il y a 2 j
Scaleway
Security Engineer - Pentester
Scaleway
⚡ Postuler tôt Paris Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
CACI
Senior Penetration Tester & Assessments Lead
CACI
⚡ Postuler tôt Remote (Any State) · lieu restreint $90,300–$189,600
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
SP
Penetration Tester
Spektrum
⚡ Postuler tôt Braine l’Alleud, Belgium Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
SP
Penetration Tester
Spektrum
⚡ Postuler tôt The Hague, Netherlands Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
CI
Senior Security Engineer, Penetration Tester
Coupang Internal
⚡ Postuler tôt Taipei, Taiwan Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 j

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Sysco

Voir tous les emplois chez Sysco →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit