A cybersecurity firm seeks an experienced application penetration tester based in the United States. You will perform manual penetration testing on APIs, web applications, and mobile applications, while leading remediation conversations with both technical and non-technical audiences. The role requires a minimum of 5 years of experience in application penetration testing and proficiency in tools like Burp Suite Pro and Netsparker. A bachelor's degree or equivalent is necessary, along with preferred ethical hacking certifications.
Qualifications
Minimum 5 years of recent experience in application penetration testing of APIs, web applications, and mobile applications.
Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations.
One or more major ethical hacking certifications preferred; GWAPT, CREST, OSWE, OSWA.
Responsibilities
Perform manual application penetration testing against APIs, web applications, mobile applications, and thick client applications.
Engage with technical and non-technical audiences to articulate testing processes and results.
Skills
Application penetration testing
Threat modeling
Communication with technical audiences
Engagement with non-technical audiences
Education
Bachelor's degree or equivalent experience
Tools
Burp Suite Pro
Netsparker
Job description
Responsibilities
Perform manual Application penetration testing against API’s (REST/SOAP), Web Applications, Mobile applications, and thick client applications
Perform threat modeling, evaluate application business logic, and perform application architecture reviews
Ability to demonstrate application testing experience in real time via demos to both internal and external audiences
Ability to perform objective based, abstract penetration testing engagements
Ability to develop and exploit POCs
Act independently in penetration testing engagements, with minimal oversight and guidance
Engage with technical and non-technical audiences to articulate both testing processes, techniques and results; guide technical audiences on remediation options and assist clients in weighing those options
Qualifications
Minimum 5 years of recent experience in application penetration testing of API’s, web applications and mobile applications
Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
Experience with burp suite pro, and other app testing tools such as Netsparker
Bachelor's degree from an accredited college/university or equivalent industry experience
One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA