About The Role
In this role you will lead application-focused penetration testing in support of products, validating that security controls work as intended. You will partner with our Engineering teams through threat modeling and software design reviews, and you will act as a trusted advisor on security issues and fixes across our development organization.
Responsibilities
- Lead and perform application-focused penetration tests, including web applications, APIs, services, and supporting infrastructure, to validate that security controls are effective
- Advise Development and Software Engineering teams on security issues and practical, well-researched fixes. Demonstrate vulnerabilities and guide remediation through to closure
- Conduct threat modeling and software design reviews early in the development lifecycle to identify risks before code ships
- Perform targeted source code reviews across technologies including Java, Struts, C#, Perl, Jetty, Envoy Proxy, and Alpine Linux based containers
- Convert technical findings into business risk and communicate it to audiences ranging from engineers to executive leadership
- Develop accurate, actionable reports and presentations for technical and executive team members
- Safely use attacker tools, techniques, and procedures within defined rules of engagement
- Develop scripts, tools, and methodologies to mature the application assessment program and support other teams
- Help define the standards, methodology, and goals for the application penetration testing program, in partnership with security leadership
- Collaborate with Application Security, Red Team, Product Management, and Engineering to support a secure by design program
- Support bug bounty triage and external penetration test engagements, including validating findings and retesting fixes
- Mentor junior team members and security champions in offensive application security techniques
Requirements
- 10 years of experience in information technology, with a minimum of 6 years in penetration testing or application security
- Software development or engineering background, with hands‑on experience in Java, Struts, C#, and Perl
- Working knowledge of Alpine Linux, Envoy Proxy, and Jetty, including common misconfigurations and hardening practices
- Proven experience with threat modeling methodologies such as STRIDE, PASTA, or attack trees, and with software design and architecture reviews
- Expert knowledge of the OWASP Top 10, OWASP API Security Top 10, and the OWASP Testing Guide / ASVS
- Deep knowledge of web and network protocols, such as HTTP/HTTPS, TLS, TCP/IP, and authentication and authorization frameworks like OAuth2, OIDC, SAML, and JWT
- Strong command of application testing tools, such as Burp Suite Professional, and familiarity with SAST, DAST, and SCA tooling
- Detailed knowledge of vulnerabilities and remediation techniques, including deserialization, injection, SSRF, access control, and business logic flaws
- Experience developing, extending, or modifying exploits or exploit tools
- Scripting and automation experience using Python, Perl, Bash, or PowerShell
- Exposure to AWS, Docker, Kubernetes, and CI/CD pipelines
- OSCP, OSWE, OSEP, GWAPT, or equivalent certification preferred
- Ability to present ideas and solutions and to communicate clearly, concisely, and accurately at all levels of the organization
- Able to drive your work to completion within specified timelines
SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.