Application Security and Penetration Testing Engineer

Agadia

Parsippany-Troy Hills (NJ)

On-site

USD 120,000 - 190,000

Full time

21 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Agadia is seeking an experienced Application Security and Penetration Testing Engineer to strengthen the security of enterprise web apps and APIs. You will perform automated and manual assessments, validate vulnerabilities, and collaborate with developers to remediate findings.

The ideal candidate combines hands-on testing with a deep understanding of secure software development and healthcare data security requirements, and will contribute to security in the SDLC and CI/CD pipelines.

Qualifications

  • Bachelor’s degree in CS/Cybersecurity/IT or equivalent professional experience.
  • 5+ years of information security, including 3+ years of hands-on web app & API testing.
  • Strong knowledge of OWASP Top 10, API Top 10, CWE, CVSS, and attack techniques.
  • Hands-on with Burp Suite Pro, OWASP ZAP, Invicti or similar DAST tools.
  • Experience testing authentication, authorization, sessions, APIs, and business logic.
  • Ability to validate findings and distinguish exploitable vulnerabilities from false positives.
  • Understanding of HTTP/HTTPS, REST, cookies, tokens, and web app architecture.
  • Familiarity with secure coding for .NET/JavaScript apps.
  • Ability to communicate vulnerabilities and remediation to technical and leadership teams.
  • Strong analytical, documentation, collaboration, and problem-solving skills.

Responsibilities

  • Conduct security assessments of web apps, APIs, and services using automated scanning and DAST.
  • Perform manual penetration testing to identify issues not seen by automation.
  • Test authentication, authorization, session mgmt, access controls, APIs, and biz logic.
  • Identify broken access control, injections, XSS, insecure configurations, exposure, and escalation.
  • Validate findings, eliminate false positives, and assess exploitability and bus. impact.
  • Document findings with evidence, reproduction steps, severity, risk, and remediation.
  • Collaborate with dev/architecture teams to advise corrective actions.
  • Retest remediated vulnerabilities and confirm closures.
  • Support secure design reviews, threat modeling, code reviews, and release readiness.
  • Help integrate security testing into SDLC and CI/CD pipelines.
  • Maintain status, timelines, risk exceptions, and assessment reports.
  • Support internal audits, customer reviews, and external pen tests.
  • Provide security guidance and training for dev and QA teams.
  • Stay current with emerging vulnerabilities, attack techniques, tools, and best practices.

Skills

Penetration testing
Threat modeling
Security assessment
Communication
Documentation
CI/CD integration

Education

Bachelors in CS/Cybersecurity/IT

Tools

Burp Suite Pro
OWASP ZAP
Invicti

Job description

Position Summary

We are seeking an experienced Application Security and Penetration Testing Engineer to strengthen the security of our enterprise web applications, APIs, and supporting services. This role will perform automated and manual security assessments, validate vulnerabilities, evaluate business risk, and collaborate with development teams to implement and verify remediation.

The ideal candidate will combine hands-on penetration testing expertise with a strong understanding of application architecture, secure software development, and healthcare data security requirements.

Key Responsibilities
  • Conduct security assessments of web applications, APIs, and related services using automated vulnerability-scanning and DAST tools.
  • Perform manual penetration testing to identify vulnerabilities that automated tools may not detect.
  • Test authentication, authorization, session management, access controls, input validation, file handling, APIs, and application business logic.
  • Identify issues such as broken access control, injection vulnerabilities, cross-site scripting, insecure configurations, information exposure, and privilege escalation.
  • Validate automated scan findings, eliminate false positives, and determine the exploitability and business impact of confirmed vulnerabilities.
  • Document findings with clear technical evidence, reproduction steps, severity, risk, business impact, and remediation recommendations.
  • Work with development and architecture teams to review findings and recommend practical corrective actions.
  • Retest remediated vulnerabilities and formally confirm their closure.
  • Support secure design reviews, threat modeling, code reviews, and release-readiness assessments.
  • Help integrate application security testing into the software development lifecycle and CI/CD pipelines.
  • Maintain vulnerability status, remediation timelines, risk exceptions, and security assessment reports.
  • Support internal audits, customer security reviews, and external penetration-testing activities.
  • Provide application security guidance and knowledge-sharing sessions for development and QA teams.
  • Stay current with emerging vulnerabilities, attack techniques, security tools, and application security best practices.
Required Qualifications
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.
  • Five or more years of information security experience, including at least three years of hands-on web application and API penetration testing.
  • Strong knowledge of the OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and common application attack techniques.
  • Hands-on experience with tools such as Burp Suite Professional, OWASP ZAP, Invicti, or comparable DAST and penetration-testing platforms.
  • Experience in manually testing authentication, authorization, session management, role-based access, APIs, and business-logic controls.
  • Ability to validate findings independently and distinguish exploitable vulnerabilities from false positives.
  • Understanding of HTTP/HTTPS, REST APIs, cookies, tokens, browser security controls, and web application architecture.
  • Familiarity with secure coding practices and application security considerations for .NET and JavaScript-based applications.
  • Ability to communicate technical vulnerabilities, business impact, and remediation guidance to both technical and leadership audiences.
  • Strong analytical, documentation, collaboration, and problem-solving skills.
Preferred Qualifications
  • Experience securing healthcare applications or other systems that handle sensitive or regulated information.
  • Knowledge of HIPAA, HITECH, HITRUST, SOC 2, NIST, and related security frameworks.
  • Experience with SAST, software composition analysis, dependency scanning, secrets scanning, and SonarQube.
  • Experience integrating security testing into Azure DevOps, GitHub, or similar CI/CD platforms.
  • Familiarity with threat modeling, secure architecture reviews, and source-code security reviews.
  • Experience testing single sign-on, OAuth 2.0, OpenID Connect, JWT, and other identity protocols.
  • Relevant certifications such as OSCP, OSWE, GWAPT, GPEN, CEH, or CISSP.
Success Measures
  • Earlier identification of application and API security risks.
  • Accurate findings with minimal false positives.
  • Clear, actionable remediation guidance for development teams.
  • Timely validation and closure of identified vulnerabilities.
  • Improved application security coverage throughout the development lifecycle.
  • Reduced dependence on periodic external penetration testing.

Please note: The Salary range is based on our market pay structure & includes benefits (Medical, Dental, Vision, life Insurance, 401 & PTO, etc.), and will be determined based on the candidate's experience, qualifications, and evaluation.

Key Competencies

Communicates effectively – Attentively listens to others, provides timely and helpful information, and is effective in a range of professional settings. Gives and receives feedback in a productive, professional manner. Demonstrates excellent oral and written communication skills.

Manages Ambiguity - Operating effectively even when things are uncertain or the way forward is unclear . Is flexible and able to adapt to meet changing business needs.

Manages complexity - Makes sense of complex , high quantity, and sometimes contradictory information to effectively solve problems. Has strong organizational skills and can manage multiple activities simultaneously. Has close attention to detail.

Ensures Accountability - Follows through on commitments and makes sure others do the same. Able to work independently as part of a small team.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Agadia • Parsippany-Troy Hills (NJ)

On-site
USD 120,000 - 180,000
Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Agadia Systems • Littleton (NJ)

On-site
USD 110,000 - 125,000
Medical benefits
Dental benefits
Vision benefits
+3
Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Cybersecurity Jobs • Parsippany-Troy Hills (NJ)

On-site
USD 110,000 - 125,000
Medical
Dental
Vision
+3
Application Security Engineer
Application Security Engineer

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth
Application Security Analyst
Application Security Analyst

AccruePartners • Fort Mill (SC)

On-site
USD 70,000 - 90,000
Ongoing investment in professional development
Exposure to modern security platforms
Collaborative team environment
Senior Application Security Tester
Senior Application Security Tester

Global Business Ser. 4u • Seattle (WA)

Hybrid
USD 140,000 - 200,000
Security Engineer, Application
Security Engineer, Application

gnw • Richmond (VA)

Hybrid
USD 78,000 - 117,000
Competitive compensation
Comprehensive healthcare coverage
401(k) with employer match
+2
Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Information Security Architect
Information Security Architect

US Anesthesia Partners • United States

On-site
USD 130,000 - 170,000
Staff DevSecOps Engineer (Health 100)
Staff DevSecOps Engineer (Health 100)

9025 CVS Shared Services Resources LLC • Massachusetts

Hybrid
USD 130,000 - 260,000