Elsevier
Elsevier is a world-leading provider of information solutions that enhance the performance of science, health, and technology.
- Open roles
- 40
- New role every
- ~0.3 days
Company signals
Score: 82Job facts
- Location
- Pennsylvania, United States of America
- Also in
- Colorado, United States of America · Connecticut, United States of America · Delaware, United States of America · Massachusetts, United States of America · Michigan, United States of America · New Jersey, United States of America · New York, United States of America · Virginia, United States of America · Philadelphia, Pennsylvania, United States of America · Pittsburgh, Pennsylvania, United States of America
- Type
- Full-time
- Posted
- Jul 31, 2026
Last verified live 16 hours, 2 minutes ago · checked directly on the company's Workday
More roles at Elsevier
- Technical Project Manger · USA - Bethesda, MD
- Health System Sales Executive, Clinical Performance · Home based-North Carolina
- Systems Engineer · Gainesville, FL (4th Avenue)
- Senior Software Engineer II · Bengaluru
- Sr Product Mgr II · London Wall
- Clinical Analytics Specialist – MD · Texas
Security Assurance Penetration Tester
at Elsevier
Are you a collaborative Penetration Tester looking to work for a mission driven global organization?
About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. This is a hands-on role for a motivated security professional eager to grow in a collaborative, fast-paced environment.
About the team - The Security Assurance team supports the third-party penetration testing program, security control validation, and ongoing offensive security testing activities.
Responsibilities
- Tracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking.
- Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture.
- Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.
- Maintaining program documentation, test records, and reporting artifacts.
- Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.
- Performing peer review of penetration testing deliverables, including test plans, findings, and final reports.
- Participating in scoping exercises and contributing to the selection of appropriate testing methodologies.
- Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
- Assisting in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.
- Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs.
Requirements
- Experience in information security, penetration testing, or a related field. Experience or coursework in software development, DevOps, or scripting is highly desirable.
- At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.
- Foundational understanding of web application architecture, networking, and operating system security.
- Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).
- Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).
- Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.
- Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations.
- Exposure to SAST/DAST tools and secure code review practices is desirable.
- Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations)
Elsevier is a renowned global information analytics company that primarily focuses on providing scientific, technical, and medical (STM) research content, tools, and services. It is one of the largest publishers of academic journals and scholarly literature in the world.
Elsevier operates in various domains, including science, technology, medicine, social sciences, and more. They publish a vast number of peer-reviewed journals covering a wide range of disciplines. These journals act as platforms for researchers and academics to share their findings and contribute to the advancement of knowledge in their respective fields.
In addition to publishing, Elsevier offers a suite of digital solutions and services to support researchers, scientists, and professionals in their work. They provide online platforms like ScienceDirect, Scopus, and Mendeley, which offer access to a vast repository of scholarly articles, research papers, and other scientific content. These platforms often serve as essential resources for software developers seeking to stay updated with the latest scientific advancements.
U.S. National Base Pay Range: $71,600 - $119,400. Geographic differentials may apply in some locations to better reflect local market rates. If performed in Colorado, the base pay range is $71,600 - $119,400.If performed in New York, the base pay range is $78,700 - $131,400.If performed in New York City, the base pay range is $85,900 - $143,300.If performed in Rochester, NY, the base pay range is $71,600 - $119,400.If performed in New Jersey, the base pay range is $84,546 - $135,054. This job is eligible for an annual incentive bonus. Application deadline is 09/17/2026.
We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click** here**to access benefits specific to your location.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scamshere.
Please read our Candidate Privacy Policy.
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers: