Application Security and Penetration Testing Engineer

Agadia Systems

Littleton (NJ)

On-site

USD 110,000 - 125,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical benefits
Dental benefits
Vision benefits
Life Insurance
401(k)
PTO

Job summary

Agadia Systems is seeking an experienced Application Security and Penetration Testing Engineer to strengthen the security of enterprise web applications, APIs, and services. The role combines automated and manual testing, vulnerability validation, and remediation verification within healthcare data security context.

The ideal candidate will have hands-on penetration testing expertise, knowledge of secure software development, and the ability to communicate findings to technical and leadership

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent professional experience.
  • Five or more years of information security experience, including at least three years of hands‑on web application and API penetration testing.
  • Strong knowledge of the OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and common application attack techniques.
  • Hands‑on experience with Burp Suite Pro, OWASP ZAP, Invicti, or comparable DAST platforms.
  • Experience testing authentication, authorization, session management, APIs, and business logic.

Responsibilities

  • Conduct security assessments of web applications, APIs, and related services using automated vulnerability-scanning and DAST tools.
  • Perform manual penetration testing to identify vulnerabilities automated tools may miss.
  • Test authentication, authorization, session management, access controls, input validation, APIs, and business logic.
  • Identify issues such as broken access control, injection vulnerabilities, XSS, insecure configurations, information exposure, and privilege escalation.
  • Validate automated findings, eliminate false positives, and determine exploitability and business impact.
  • Document findings with evidence, severity, risk, business impact, and remediation recommendations.
  • Collaborate with development and architecture teams to review findings and recommend corrective actions.
  • Retest remediated vulnerabilities and confirm closure.
  • Support secure design reviews, threat modeling, code reviews, and release-readiness assessments.
  • Help integrate application security testing into SDLC and CI/CD pipelines.
  • Maintain vulnerability status, remediation timelines, risk exceptions, and assessment reports.
  • Support internal audits and customer security reviews.

Skills

Penetration testing
Web security
Secure SDLC
OWASP Top 10
Vulnerability assessment
Communication skills

Education

Bachelor's degree in CS/Cybersecurity/IT

Tools

Burp Suite Pro
OWASP ZAP
Invicti
DAST tools

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Application Security and Penetration Testing Engineer

Full Time Parsippany, NJ, US

2 days ago Requisition ID: 1022

Salary Range: $110,000.00 To $125,000.00 Annually

Position Summary

We are seeking an experienced Application Security and Penetration Testing Engineer to strengthen the security of our enterprise web applications, APIs, and supporting services. This role will perform automated and manual security assessments, validate vulnerabilities, evaluate business risk, and collaborate with development teams to implement and verify remediation.

The ideal candidate will combine hands-on penetration testing expertise with a strong understanding of application architecture, secure software development, and healthcare data security requirements.

Key Responsibilities

  • Conduct security assessments of web applications, APIs, and related services using automated vulnerability-scanning and DAST tools.
  • Perform manual penetration testing to identify vulnerabilities that automated tools may not detect.
  • Test authentication, authorization, session management, access controls, input validation, file handling, APIs, and application business logic.
  • Identify issues such as broken access control, injection vulnerabilities, cross-site scripting, insecure configurations, information exposure, and privilege escalation.
  • Validate automated scan findings, eliminate false positives, and determine the exploitability and business impact of confirmed vulnerabilities.
  • Document findings with clear technical evidence, reproduction steps, severity, risk, business impact, and remediation recommendations.
  • Work with development and architecture teams to review findings and recommend practical corrective actions.
  • Retest remediated vulnerabilities and formally confirm their closure.
  • Support secure design reviews, threat modeling, code reviews, and release-readiness assessments.
  • Help integrate application security testing into the software development lifecycle and CI/CD pipelines.
  • Maintain vulnerability status, remediation timelines, risk exceptions, and security assessment reports.
  • Support internal audits, customer security reviews, and external penetration-testing activities.
  • Provide application security guidance and knowledge-sharing sessions for development and QA teams.
  • Stay current with emerging vulnerabilities, attack techniques, security tools, and application security best practices.

Required Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.
  • Five or more years of information security experience, including at least three years of hands‑on web application and API penetration testing.
  • Strong knowledge of the OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and common application attack techniques.
  • Hands‑on experience with tools such as Burp Suite Professional, OWASP ZAP, Invicti, or comparable DAST and penetration‑testing platforms.
  • Experience in manually testing authentication, authorization, session management, role‑based access, APIs, and business‑logic controls.
  • Ability to validate findings independently and distinguish exploitable vulnerabilities from false positives.
  • Ability to communicate technical vulnerabilities, business impact, and remediation guidance to both technical and leadership audiences.
  • Strong analytical, documentation, collaboration, and problem‑solving skills.

Preferred Qualifications

  • Experience securing healthcare applications or other systems that handle sensitive or regulated information.
  • Knowledge of HIPAA, HITECH, HITRUST, SOC 2, NIST, and related security frameworks.
  • Experience with SAST, software composition analysis, dependency scanning, secrets scanning, and SonarQube.
  • Experience integrating security testing into Azure DevOps, GitHub, or similar CI/CD platforms.
  • Familiarity with threat modeling, secure architecture reviews, and source‑code security reviews.
  • Experience testing single sign‑on, OAuth 2.0, OpenID Connect, JWT, and other identity protocols.
  • Relevant certifications such as OSCP, OSWE, GWAPT, GPEN, CEH, or CISSP.

Success Measures

  • Earlier identification of application and API security risks.
  • Accurate findings with minimal false positives.
  • Clear, actionable remediation guidance for development teams.
  • Timely validation and closure of identified vulnerabilities.
  • Improved application security coverage throughout the development lifecycle.
  • Reduced dependence on periodic external penetration testing.

Please note:The Salary range is based on our market pay structure & includes benefits (Medical, Dental, Vision, life Insurance, 401 & PTO, etc.), and will be determined based on the candidate's experience, qualifications, and evaluation.

Communicates effectively – Attentively listens to others, provides timely and helpful information, and is effective in a range of professional settings. Gives and receives feedback in a productive, professional manner. Demonstrates excellent oral and written communication skills.

Manages Ambiguity - Operating effectively even when things are uncertain or the way forward is unclear . Is flexible and able to adapt to meet changing business needs.

Manages complexity - Makes sense of complex , high quantity, and sometimes contradictory information to effectively solve problems. Has strong organizational skills and can manage multiple activities simultaneously. Has close attention to detail.

Ensures Accountability - Follows through on commitments and makes sure others do the same. Able to work independently as part of a small team.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Agadia • Parsippany-Troy Hills (NJ)

On-site
USD 120,000 - 180,000
Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Cybersecurity Jobs • Parsippany-Troy Hills (NJ)

On-site
USD 110,000 - 125,000
Medical
Dental
Vision
+3
Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Agadia • Parsippany-Troy Hills (NJ)

On-site
USD 120,000 - 190,000
Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Penetration Tester
Penetration Tester

Saic • Town of Texas (WI)

On-site
USD 120,000 - 160,000
Remote Penetration Tester
Remote Penetration Tester

Philadelphia Comapny • Atlanta (GA)

Remote
USD 80,000 - 120,000
Application Security Engineer
Application Security Engineer

The Amatriot Group • City of Rensselaer (NY)

On-site
USD 90,000 - 110,000
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa | restb.ai • United States

Remote
USD 111,000 - 144,000
Profit-sharing bonus program
Communication stipends
Referral bonuses
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Principal Engineer, IT Security
Principal Engineer, IT Security

Quest Diagnostics Incorporated • Secaucus (NJ)

On-site
USD 160,000 - 170,000
Day 1 Medical & dental
401(k) with company match
Annual incentive programs
+1