MKS2 Technologies is seeking an Ethical Hacker / Penetration Tester Principal to help secure a large-scale enterprise application environment. The role focuses on identifying, exploiting, assessing, and remediating vulnerabilities in Java-based applications and supporting infrastructure, in partnership with teams across the SDLC and DevSecOps lifecycle.
Location and Schedule
- Location: New York, NY (Hybrid)
- Work pattern: Remote with travel to Albany, NY twice per month (two trips per month)
- Job Type: Full-Time
- Program: NYSoH
- Hours: 40 hours per week
Salary
- Compensation: USD 120,000 per year
Key Responsibilities
- Perform penetration testing and vulnerability assessments for Java applications, APIs, and supporting infrastructure.
- Execute manual and automated security testing to uncover application vulnerabilities.
- Develop and run custom exploits to model real-world attacker behaviors.
- Review application architecture and source code to identify security risks and likely attack vectors.
- Collaborate with development teams to integrate security earlier in the SDLC.
- Work with QA and automation teams to incorporate security testing into release processes.
- Review source code and provide guidance aligned with secure remediation practices.
- Assess browser tokens, session management, caching, and authentication mechanisms.
- Test exploitation opportunities by manipulating URLs, query parameters, browser data, and application workflows.
- Support incident response activities related to security vulnerabilities and published CVE information.
- Create detailed reports covering findings, risk levels, business impact, and remediation recommendations.
- Deliver security findings to both technical and non-technical stakeholders.
- Contribute to security standards, policies, and secure development practices.
- Stay current on emerging threats, attack techniques, and industry best practices.
- Use methodologies aligned with MITRE ATT&CK and OWASP guidelines.
Required Qualifications
- Education: Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related technical field
- Experience: Minimum of 6 years of software development and security experience
- Prior experience in a DevSecOps, Application Security, Security Engineering, or Penetration Testing role
- Strong hands-on Java development experience
- Experience supporting large-scale enterprise applications
- Knowledge of secure coding principles and application security best practices
- Experience performing penetration testing against web applications and services
- Strong understanding of OWASP Top 10 vulnerabilities and mitigation techniques
- Experience using security testing tools, including: Burp Suite, Metasploit, web proxy tools, and vulnerability assessment platforms
- Experience with Static and Dynamic Application Security Testing (SAST/DAST), including: Fortify on Demand (SAST) and Fortify on Demand (DAST)
- Knowledge of web vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), Authentication & Authorization Flaws, Session Management Vulnerabilities, and API Security Risks
- Strong understanding of cryptography and secure communications protocols (SSL/TLS)
- Excellent analytical, troubleshooting, and problem-solving skills
- Strong written and verbal communication abilities
- Demonstrated professionalism, ethics, and confidentiality
Preferred Qualifications
- OSCP (Offensive Security Certified Professional)
- GWAPT (GIAC Web Application Penetration Tester)
- GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)
- GPEN (GIAC Penetration Tester)
- LPT (Licensed Penetration Tester)
- CEH (Certified Ethical Hacker)
- CISSP (Certified Information Systems Security Professional)
- Experience with Python, Bash, or other scripting languages
- Experience performing secure code reviews for Java applications
- Knowledge of cloud security testing methodologies
- Mobile application penetration testing experience
- Experience conducting API security assessments
- Familiarity with HIPAA and regulated environments
- Knowledge of vulnerability management and CVE remediation processes
Technologies and Methodologies
- Java
- Burp Suite
- Metasploit
- Fortify on Demand (SAST)
- Fortify on Demand (DAST)
- MITRE ATT&CK Framework
- OWASP
- SSL/TLS
- SQL Injection, Cross-Site Scripting (XSS)
- Authentication & Authorization Flaws
- Session Management Vulnerabilities
- API Security Risks
- SAST/DAST
- DevSecOps, API Security
- Threat Modeling, Risk Assessment
Security Clearance
- Clearance Required: None
- Citizenship Requirement: None
Why Join MKS2 Technologies
- Work on mission-critical enterprise applications.
- Collaborate with a highly skilled cybersecurity team.
- Influence secure development practices across large-scale environments.
- Gain exposure to advanced security testing technologies and methodologies.
- Make a direct impact on application security and cyber resilience.