Agadia Systems Inc seeks an Application Security and Penetration Testing Engineer to strengthen enterprise web application and API security through automated and manual testing, validation, and remediation collaboration.
Responsibilities
- Conduct security assessments of web applications, APIs, and supporting services using automated vulnerability scanning and DAST tools.
- Perform manual penetration testing to uncover vulnerabilities that automated tooling may miss.
- Test authentication, authorization, session management, and access controls, including role-based and business-logic enforcement.
- Evaluate input validation, file handling, API behavior, and application business logic.
- Identify and assess issues including broken access control, injection, cross-site scripting, insecure configurations, information exposure, and privilege escalation.
- Validate scan results by eliminating false positives and determining exploitability and business impact for confirmed vulnerabilities.
- Document findings with technical evidence, reproduction steps, severity, risk, business impact, and remediation recommendations.
- Partner with development and architecture teams to review results and recommend practical fixes.
- Retest remediated issues and formally confirm vulnerability closure.
- Support secure design reviews, threat modeling, code reviews, and release-readiness assessments.
- Help integrate application security testing into the software development lifecycle and CI/CD pipelines.
- Maintain vulnerability status, remediation timelines, risk exceptions, and security assessment reports.
- Support internal audits, customer security reviews, and external penetration-testing activities.
- Provide application security guidance and knowledge-sharing for development and QA teams.
- Stay current on emerging vulnerabilities, attack techniques, security tools, and application security best practices.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related discipline (or equivalent professional experience).
- 5+ years of information security experience, including at least 3 years hands‑on web application and API penetration testing.
- Strong knowledge of OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and common application attack techniques.
- Hands‑on tool experience with Burp Suite Professional, OWASP ZAP, Invicti, or comparable DAST and penetration‑testing platforms.
- Ability to manually test authentication, authorization, session management, role‑based access, API controls, and business‑logic enforcement.
- Capability to validate findings independently and differentiate exploitable vulnerabilities from false positives.
- Knowledge of HTTP/HTTPS, REST APIs, cookies, tokens, browser security controls, and web application architecture.
- Familiarity with secure coding practices and application security considerations for .NET and JavaScript‑based applications.
- Ability to communicate technical vulnerabilities, business impact, and remediation guidance to technical and leadership audiences.
- Strong analytical, documentation, collaboration, and problem‑solving skills.
Technologies
- Burp Suite Professional
- OWASP ZAP
- Invicti
- DAST
- OWASP Top 10
- OWASP API Security Top 10
- CWE
- CVSS
- HTTP/HTTPS
- REST APIs
- .NET
- JavaScript
- Azure DevOps
- GitHub
- SAST
- Software composition analysis
- Dependency scanning
- Secrets scanning
- SonarQube
- Threat modeling
- OAuth 2.0
- OpenID Connect
- JWT
Preferred Qualifications
- Experience securing healthcare applications or other systems handling sensitive or regulated information.
- Knowledge of HIPAA, HITECH, HITRUST, SOC 2, NIST, and related security frameworks.
- Experience with SAST, software composition analysis, dependency scanning, secrets scanning, and SonarQube.
- Experience integrating security testing into Azure DevOps, GitHub, or similar CI/CD platforms.
- Familiarity with threat modeling, secure architecture reviews, and source‑code security reviews.
- Experience testing single sign‑on, OAuth 2.0, OpenID Connect, JWT, and other identity protocols.
- Relevant certifications such as OSCP, OSWE, GWAPT, GPEN, CEH, or CISSP.
Benefits
- Medical
- Dental
- Vision
- Life Insurance
- 401
- PTO
Success Measures
- Earlier identification of application and API security risks.
- Accurate findings with minimal false positives.
- Clear, actionable remediation guidance for development teams.
- Timely validation and closure of identified vulnerabilities.
- Improved application security coverage throughout the development lifecycle.
- Reduced dependence on periodic external penetration testing.
Key Competencies
- Communicates effectively: provides timely information, gives and receives feedback productively, demonstrates strong oral and written communication.
- Manages ambiguity: operates effectively when uncertain, adapts to changing business needs.
- Manages complexity: handles complex, high‑volume, sometimes contradictory information; strong organizational skills and attention to detail.
- Ensures accountability: follows through on commitments; works independently as part of a small team.
Location: Parsippany‑Troy Hills, NJ (onsite)
Salary: USD 110,000 - 125,000 per yearly