Application Security and Penetration Testing Engineer

Agadia

Parsippany-Troy Hills (NJ)

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

RXinsider LTD. in Parsippany, NJ seeks an experienced Application Security and Penetration Testing Engineer to strengthen security of enterprise web apps and APIs.

You will perform automated and manual assessments, validate findings, and collaborate with development teams to verify remediation across the software lifecycle. The ideal candidate brings hands-on pentesting expertise, solid knowledge of OWASP Top 10 and API security, and the ability to communicate risks to technical and leadership

Qualifications

  • Bachelor’s degree in a related field or equivalent professional experience.
  • 5+ years in information security with hands-on web app and API testing.
  • Strong knowledge of OWASP Top 10, API Top 10, CWE, CVSS and attack techniques.
  • Experience with Burp Suite Pro, OWASP ZAP, Invicti or similar tools.
  • Ability to validate findings and distinguish exploitable vulnerabilities from false positives.
  • Clear communication of vulnerabilities, business impact, and remediation guidance.

Responsibilities

  • Conduct security assessments of web apps, APIs, and related services using automated vulnerability-scanning and manual testing.
  • Test authentication, authorization, session management, APIs, and business logic.
  • Validate findings, document evidence, severity, and remediation recommendations.
  • Collaborate with development/architecture teams to remediate vulnerabilities and retest.
  • Support secure design reviews, threat modeling, code reviews, and CI/CD integration.
  • Provide application security guidance and knowledge sharing for teams.

Skills

Burp Suite Professional
OWASP Top 10
OWASP API Security Top 10
DAST Tools
Web API security testing
Authentication & Authorization testing
Secure coding practices (.NET, Java/JS
Communication of vulnerabilities

Education

Bachelor's degree or equivalent

Tools

Burp Suite Pro
OWASP ZAP
Invicti

Job description

Position Summary

We are seeking an experienced Application Security and Penetration Testing Engineer to strengthen the security of our enterprise web applications, APIs, and supporting services. This role will perform automated and manual security assessments, validate vulnerabilities, evaluate business risk, and collaborate with development teams to implement and verify remediation.

The ideal candidate will combine hands‑on penetration testing expertise with a strong understanding of application architecture, secure software development, and healthcare data security requirements.

Key Responsibilities
  • Conduct security assessments of web applications, APIs, and related services using automated vulnerability-scanning and DAST tools.
  • Perform manual penetration testing to identify vulnerabilities that automated tools may not detect.
  • Test authentication, authorization, session management, access controls, input validation, file handling, APIs, and application business logic.
  • Identify issues such as broken access control, injection vulnerabilities, cross‑site scripting, insecure configurations, information exposure, and privilege escalation.
  • Validate automated scan findings, eliminate false positives, and determine the exploitability and business impact of confirmed vulnerabilities.
  • Document findings with clear technical evidence, reproduction steps, severity, risk, business impact, and remediation recommendations.
  • Work with development and architecture teams to review findings and recommend practical corrective actions.
  • Retest remediated vulnerabilities and formally confirm their closure.
  • Support secure design reviews, threat modeling, code reviews, and release‑readiness assessments.
  • Help integrate application security testing into the software development lifecycle and CI/CD pipelines.
  • Maintain vulnerability status, remediation timelines, risk exceptions, and security assessment reports.
  • Support internal audits, customer security reviews, and external penetration‑testing activities.
  • Provide application security guidance and knowledge‑sharing sessions for development and QA teams.
  • Stay current with emerging vulnerabilities, attack techniques, security tools, and application security best practices.
Required Qualifications
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.
  • Five or more years of information security experience, including at least three years of hands‑on web application and API penetration testing.
  • Strong knowledge of the OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and common application attack techniques.
  • Hands‑on experience with tools such as Burp Suite Professional, OWASP ZAP, Invicti, or comparable DAST and penetration‑testing platforms.
  • Experience in manually testing authentication, authorization, session management, role‑based access, APIs, and business‑logic controls.
  • Ability to validate findings independently and distinguish exploitable vulnerabilities from false positives.
  • Understanding of HTTP/HTTPS, REST APIs, cookies, tokens, browser security controls, and web application architecture.
  • Familiarity with secure coding practices and application security considerations for .NET and JavaScript‑based applications.
  • Ability to communicate technical vulnerabilities, business impact, and remediation guidance to both technical and leadership audiences.
  • Strong analytical, documentation, collaboration, and problem‑solving skills.
Preferred Qualifications
  • Experience securing healthcare applications or other systems that handle sensitive or regulated information.
  • Knowledge of HIPAA, HITECH, HITRUST, SOC 2, NIST, and related security frameworks.
  • Experience with SAST, software composition analysis, dependency scanning, secrets scanning, and SonarQube.
  • Experience integrating security testing into Azure DevOps, GitHub, or similar CI/CD platforms.
  • Familiarity with threat modeling, secure architecture reviews, and source‑code security reviews.
  • Experience testing single sign‑on, OAuth 2.0, OpenID Connect, JWT, and other identity protocols.
  • Relevant certifications such as OSCP, OSWE, GWAPT, GPEN, CEH, or CISSP.
Success Measures
  • Earlier identification of application and API security risks.
  • Accurate findings with minimal false positives.
  • Clear, actionable remediation guidance for development teams.
  • Timely validation and closure of identified vulnerabilities.
  • Improved application security coverage throughout the development lifecycle.
  • Reduced dependence on periodic external penetration testing.
Please note:

The Salary range is based on our market pay structure & includes benefits (Medical, Dental, Vision, life Insurance, 401 & PTO, etc.), and will be determined based on the candidate's experience, qualifications, and evaluation.

Key Competencies

Communicates effectively – Attentively listens to others, provides timely and helpful information, and is effective in a range of professional settings. Gives and receives feedback in a productive, professional manner. Demonstrates excellent oral and written communication skills. Manages Ambiguity – Operating effectively even when things are uncertain or the way forward is unclear. Is flexible and able to adapt to meet changing business needs. Manages complexity – Makes sense of complex , high quantity, and sometimes contradictory information to effectively solve problems. Has strong organizational skills and can manage multiple activities simultaneously. Has close attention to detail. Ensures Accountability – Follows through on commitments and makes sure others do the same. Able to work independently as part of a small team.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Agadia • Parsippany-Troy Hills (NJ)

On-site
USD 120,000 - 190,000
Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Agadia Systems • Littleton (NJ)

On-site
USD 110,000 - 125,000
Medical benefits
Dental benefits
Vision benefits
+3
Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Cybersecurity Jobs • Parsippany-Troy Hills (NJ)

On-site
USD 110,000 - 125,000
Medical
Dental
Vision
+3
Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Penetration Tester
Penetration Tester

Saic • Town of Texas (WI)

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Remote Penetration Tester
Remote Penetration Tester

Philadelphia Comapny • Atlanta (GA)

Remote
USD 80,000 - 120,000
Application Security (AppSec) Engineer - W2 Only
Application Security (AppSec) Engineer - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 110,000 - 160,000
Application Security Engineer
Application Security Engineer

Spry Methods, Inc. • Washington

On-site
USD 120,000 - 160,000
Medical coverage
Dental coverage
Vision coverage
+4
Application Security Engineer
Application Security Engineer

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth