Application Security and Penetration Testing Engineer

Cybersecurity Jobs

Parsippany-Troy Hills (NJ)

On-site

USD 110,000 - 125,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
Life Insurance
401
PTO

Job summary

Agadia Systems Inc seeks an Application Security and Penetration Testing Engineer to strengthen enterprise web application and API security through automated and manual testing, validation, and remediation collaboration.

Responsibilities include security assessments of web apps, APIs, and services; manual penetration testing; testing authentication, authorization, session management, and RBAC; and providing remediation recommendations.

Qualifications

  • Bachelor's degree in CS, Cybersecurity, IT, or equivalent experience.
  • 5+ years information security with 3+ years web app/API pentesting.
  • Know OWASP Top 10, API Top 10, CWE, CVSS; strong testing techniques.
  • Experience with Burp Suite Pro, OWASP ZAP, Invicti or similar tools.
  • Ability to communicate vulnerabilities and remediation guidance.

Responsibilities

  • Conduct security assessments of web apps, APIs, and services using automated scanners and manual testing.
  • Perform manual penetration testing to uncover hidden vulnerabilities.
  • Test authentication, authorization, session management, RBAC, and API controls.
  • Validate findings, document evidence, risk, business impact, and remediation steps.
  • Retest remediated issues and support secure SDLC and CI/CD processes.
  • Collaborate with development and architecture teams to fix issues.

Skills

Penetration testing
Web security
Threat modeling
Documentation
Communication

Education

Bachelor's degree in CS/Cybersecurity

Tools

Burp Suite Pro
OWASP ZAP
Invicti
DAST tools

Job description

Agadia Systems Inc seeks an Application Security and Penetration Testing Engineer to strengthen enterprise web application and API security through automated and manual testing, validation, and remediation collaboration.

Responsibilities
  • Conduct security assessments of web applications, APIs, and supporting services using automated vulnerability scanning and DAST tools.
  • Perform manual penetration testing to uncover vulnerabilities that automated tooling may miss.
  • Test authentication, authorization, session management, and access controls, including role-based and business-logic enforcement.
  • Evaluate input validation, file handling, API behavior, and application business logic.
  • Identify and assess issues including broken access control, injection, cross-site scripting, insecure configurations, information exposure, and privilege escalation.
  • Validate scan results by eliminating false positives and determining exploitability and business impact for confirmed vulnerabilities.
  • Document findings with technical evidence, reproduction steps, severity, risk, business impact, and remediation recommendations.
  • Partner with development and architecture teams to review results and recommend practical fixes.
  • Retest remediated issues and formally confirm vulnerability closure.
  • Support secure design reviews, threat modeling, code reviews, and release-readiness assessments.
  • Help integrate application security testing into the software development lifecycle and CI/CD pipelines.
  • Maintain vulnerability status, remediation timelines, risk exceptions, and security assessment reports.
  • Support internal audits, customer security reviews, and external penetration-testing activities.
  • Provide application security guidance and knowledge-sharing for development and QA teams.
  • Stay current on emerging vulnerabilities, attack techniques, security tools, and application security best practices.
Requirements
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related discipline (or equivalent professional experience).
  • 5+ years of information security experience, including at least 3 years hands‑on web application and API penetration testing.
  • Strong knowledge of OWASP Top 10, OWASP API Security Top 10, CWE, CVSS, and common application attack techniques.
  • Hands‑on tool experience with Burp Suite Professional, OWASP ZAP, Invicti, or comparable DAST and penetration‑testing platforms.
  • Ability to manually test authentication, authorization, session management, role‑based access, API controls, and business‑logic enforcement.
  • Capability to validate findings independently and differentiate exploitable vulnerabilities from false positives.
  • Knowledge of HTTP/HTTPS, REST APIs, cookies, tokens, browser security controls, and web application architecture.
  • Familiarity with secure coding practices and application security considerations for .NET and JavaScript‑based applications.
  • Ability to communicate technical vulnerabilities, business impact, and remediation guidance to technical and leadership audiences.
  • Strong analytical, documentation, collaboration, and problem‑solving skills.
Technologies
  • Burp Suite Professional
  • OWASP ZAP
  • Invicti
  • DAST
  • OWASP Top 10
  • OWASP API Security Top 10
  • CWE
  • CVSS
  • HTTP/HTTPS
  • REST APIs
  • .NET
  • JavaScript
  • Azure DevOps
  • GitHub
  • SAST
  • Software composition analysis
  • Dependency scanning
  • Secrets scanning
  • SonarQube
  • Threat modeling
  • OAuth 2.0
  • OpenID Connect
  • JWT
Preferred Qualifications
  • Experience securing healthcare applications or other systems handling sensitive or regulated information.
  • Knowledge of HIPAA, HITECH, HITRUST, SOC 2, NIST, and related security frameworks.
  • Experience with SAST, software composition analysis, dependency scanning, secrets scanning, and SonarQube.
  • Experience integrating security testing into Azure DevOps, GitHub, or similar CI/CD platforms.
  • Familiarity with threat modeling, secure architecture reviews, and source‑code security reviews.
  • Experience testing single sign‑on, OAuth 2.0, OpenID Connect, JWT, and other identity protocols.
  • Relevant certifications such as OSCP, OSWE, GWAPT, GPEN, CEH, or CISSP.
Benefits
  • Medical
  • Dental
  • Vision
  • Life Insurance
  • 401
  • PTO
Success Measures
  • Earlier identification of application and API security risks.
  • Accurate findings with minimal false positives.
  • Clear, actionable remediation guidance for development teams.
  • Timely validation and closure of identified vulnerabilities.
  • Improved application security coverage throughout the development lifecycle.
  • Reduced dependence on periodic external penetration testing.
Key Competencies
  • Communicates effectively: provides timely information, gives and receives feedback productively, demonstrates strong oral and written communication.
  • Manages ambiguity: operates effectively when uncertain, adapts to changing business needs.
  • Manages complexity: handles complex, high‑volume, sometimes contradictory information; strong organizational skills and attention to detail.
  • Ensures accountability: follows through on commitments; works independently as part of a small team.

Location: Parsippany‑Troy Hills, NJ (onsite)

Salary: USD 110,000 - 125,000 per yearly

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Agadia Systems • Littleton (NJ)

On-site
USD 110,000 - 125,000
Medical benefits
Dental benefits
Vision benefits
+3
Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Agadia • Parsippany-Troy Hills (NJ)

On-site
USD 120,000 - 180,000
Application Security and Penetration Testing Engineer
Application Security and Penetration Testing Engineer

Agadia • Parsippany-Troy Hills (NJ)

On-site
USD 120,000 - 190,000
Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Application Security Analyst
Application Security Analyst

AccruePartners • Fort Mill (SC)

On-site
USD 70,000 - 90,000
Ongoing investment in professional development
Exposure to modern security platforms
Collaborative team environment
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Penetration Tester
Penetration Tester

Saic • Town of Texas (WI)

On-site
USD 120,000 - 160,000
IT Application Security Manager
IT Application Security Manager

Cybersecurity Jobs • Lakewood (CO)

Hybrid
USD 130,000 - 190,000
401(k) plan with matching
Medical, dental, and vision plans
Wellness program
+2
Penetration Tester
Penetration Tester

Saic • Texas

Hybrid
USD 120,000 - 160,000
Application Security Engineer
Application Security Engineer

Spry Methods, Inc. • Washington

On-site
USD 120,000 - 160,000
Medical coverage
Dental coverage
Vision coverage
+4