Cyber Security Web Application Research Engineer

Jobtailor

Arizona

Hybrid

USD 90,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Jobtailor seeks a Cyber Security Researcher to perform penetration testing on web, mobile, and API surfaces using manual techniques and automated tools. You will configure scanners, analyze findings, validate results, and deliver thorough reports.

Collaboration with developers and security teams is essential to clarify defects and drive remediation. The role embraces AI-assisted testing and requires strong communication.

Qualifications

  • 2+ years of Cyber Security Research experience or equivalent
  • 2+ years of Web application penetration testing
  • 2+ years of Dynamic Application Security Testing (DAST)
  • Advanced experience with DAST tools: Invicti, AppScan, WebInspect, Fiddler, Burp Suite
  • Knowledge of OWASP Top 10 and security best practices
  • Experience with scripting/automation (Python, Shell)
  • Security standards knowledge (PCI DSS, GDPR)
  • Excellent communication and cross-functional collaboration

Responsibilities

  • Conduct application penetration testing for web apps, mobile apps, and APIs using manual and automated techniques
  • Configure automated tools to complete successful scanning
  • Analyze defects, review and validate automated scan results, and triage false positives
  • Generate accurate and detailed technical reports with identified defects
  • Collaborate with development and security teams to clarify defects and remediation paths
  • Support continuous improvement of testing methodologies and processes per industry standards
  • Share knowledge and perform peer reviews of reports with team members
  • Communicate with diverse stakeholders
  • Demonstrate proficiency with AI-enhanced security scanners and tools
  • Leverage AI to accelerate defect identification and validation
  • Apply technical judgment when validating and integrating AI-assisted outputs
  • Account for model limitations, security risks, and operational considerations
  • Ensure AI usage aligns with security, compliance, privacy, and ethical standards

Skills

Excellent communication
Problem solving
Analytical skills
Collaboration skills
Security knowledge

Education

Certifications

Tools

Invicti
AppScan
WebInspect
Fiddler
Burp Suite
AI Security Tools

Job description

  • Conduct application penetration testing for web applications, mobile applications, and APIs using manual penetration testing skills and automated tools
  • Configure automated tools to complete successful scanning
  • Analyze defects, review and validate automated scan results, and triage and disposition false positives
  • Generate accurate and detailed technical reports with identified defects
  • Collaborate with development and security teams to clarify defects and remediation paths
  • Support continuous improvement of testing methodologies and processes using industry standards and best practices
  • Share knowledge and complete peer reviews of reports with team members
  • Communicate with various stakeholders
  • Demonstrate proficiency in using AI-enhanced security scanners and tools
  • Leverage AI to accelerate defect identification and validation
  • Apply technical judgment when validating and integrating AI-assisted outputs into solutions
  • Account for model limitations, security risks, and operational considerations
  • Ensure AI usage aligns with security, compliance, privacy, and ethical standards
Requirements
  • 2+ years of Cyber Security Research experience, or equivalent demonstrated through work experience, training, military experience, or education
  • 2+ years of Web application penetration testing
  • 2+ years Dynamic Application Security Testing (DAST)
  • Advanced experience in DAST tools such as Invicti, Appscan, Webinspect, Fiddler, and Burp Suite
  • Advanced knowledge of application security and common vulnerabilities, including OWASP Top 10
  • Experience with scripting and automation, such as Python and Shell
  • Knowledge of security best practices and compliance standards, such as PCI DSS and GDPR
  • Excellent communication skills and ability to collaborate effectively with cross-functional teams
  • Strong problem-solving and analytical skills
  • Security certifications such as OSCP, BSCP, GWAPT, GPEN, or GXPN are a plus
  • Ability to work a hybrid schedule: 3 days per week on-site/in office and 2 days per week remote
  • This position is not eligible for Visa sponsorship
Core Competencies

Proficient in conducting application penetration testing for web and mobile applications, utilizing advanced DAST tools and AI-enhanced security scanners. Strong ability to analyze vulnerabilities, generate detailed reports, and collaborate with cross-functional teams to ensure compliance with security standards.

Highest-signal resume keywords
  • Web Application Penetration Testing
  • Dynamic Application Security Testing (DAST)
  • Advanced DAST Tools (Invicti, Appscan, Webinspect, Fiddler, Burp Suite)
  • Scripting and Automation (Python, Shell)
  • Security Certifications (OSCP, BSCP, GWAPT, GPEN, GXPN)
Hard Skills
  • Application Penetration Testing
  • Dynamic Application Security Testing (DAST)
  • Vulnerability Analysis
  • Technical Report Generation
  • Scripting (Python, Shell)
  • AI-Enhanced Security Scanners
  • Defect Validation
  • Compliance Standards (PCI DSS, GDPR)
  • Security Best Practices
  • Collaboration with Development Teams
Soft Skills
  • Excellent Communication Skills
  • Problem-Solving Skills
  • Analytical Skills
  • Collaboration Skills
Certifications & Qualifications
  • OSCP
  • BSCP
  • GWAPT
  • GPEN
  • GXPN
Industry Keywords
  • Cyber Security
  • Application Security
  • OWASP Top 10
  • Compliance
  • Security Risks
  • Ethical Standards
Tools & Technologies
  • Invicti
  • Appscan
  • Webinspect
  • Fiddler
  • Burp Suite
  • AI Security Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Jobtailor • Denver (CO)

On-site
USD 140,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Penetration Testing Engineer II
Penetration Testing Engineer II

Jobtailor • Bentonville (AR)

On-site
USD 80,000 - 110,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
IT Security Auditor
IT Security Auditor

Jobtailor • Missouri

On-site
USD 120,000 - 180,000
Security Engineer, Application Security
Security Engineer, Application Security

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Senior Associate – Cybersecurity Analyst
Senior Associate – Cybersecurity Analyst

Jobtailor • New York (NY)

On-site
USD 30,000 - 48,000
Senior Staff Product Security Engineer – AI
Senior Staff Product Security Engineer – AI

Jobtailor • Illinois

On-site
USD 140,000 - 220,000
Technical Lead, Security Embedded Engineering
Technical Lead, Security Embedded Engineering

Jobtailor • Plano (TX)

On-site
USD 140,000 - 180,000
Cybersecurity Intern
Cybersecurity Intern

Jobtailor • United States

Hybrid
USD 28,000 - 41,000