penetration tester

penetration tester

Posted Today by 1763108895

Negotiable
Outside
Remote
USA

Summary: The role of a penetration tester involves conducting manual penetration testing on various applications, including web, mobile, and APIs. The position requires independent engagement in testing activities and effective communication of results to both technical and non-technical audiences. Candidates should have significant experience in application penetration testing and be able to demonstrate their skills in real-time scenarios. A strong understanding of application security and threat modeling is essential for success in this role.

Key Responsibilities:

  • Perform manual Application penetration testing against APIs (REST/SOAP), Web Applications, Mobile applications, and thick client applications
  • Perform threat modeling, evaluate application business logic, and perform application architecture reviews
  • Ability to demonstrate application testing experience in real time via demos to both internal and external audiences
  • Ability to perform objective based, abstract penetration testing engagements
  • Ability to develop and exploit POCs
  • Act independently in penetration testing engagements, with minimal oversight and guidance
  • Engage with technical and non-technical audiences to articulate both testing processes, techniques and results; guide technical audiences on remediation options and assist clients in weighing those options

Key Skills:

  • Minimum 5 years of recent experience in application penetration testing of APIs, web applications, and mobile applications
  • Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
  • Experience with Burp Suite Pro, and other app testing tools such as Netsparker
  • Bachelor's degree from an accredited college/university or equivalent industry experience
  • One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA

Salary (Rate): undetermined

City: undetermined

Country: USA

Working Arrangements: remote

IR35 Status: outside IR35

Seniority Level: undetermined

Industry: IT

Detailed Description From Employer:

Job Title: penetration tester Location: Remote

Manual Penetration Testing

Web Applications

Mobile Applications

API s

Responsibilities:

  • Perform manual Application penetration testing against API s (REST/SOAP), Web Applications, Mobile applications, and thick client applications
    Perform threat modeling, evaluate application business logic, and perform application architecture reviews
    Ability to demonstrate application testing experience in real time via demos to both internal and external audiences
    Ability to perform objective based, abstract penetration testing engagements
    Ability to develop and exploit POCs
    Act independently in penetration testing engagements, with minimal oversight and guidance
    Engage with technical and non-technical audiences to articulate both testing processes, techniques and results; guide technical audiences on remediation options and assist clients in weighing those options

Qualifications:

  • Minimum 5years of recent experience in application penetration testing of API s, web applicationsand mobile applications
    Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
    Experience with burp suite pro, and other app testing tools such as Netsparker
    Bachelor's degree from an accredited college/university or equivalent industry experience
    One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA