Penetration Tester

Deloitte France

Tampa (FL)

On-site

USD 90,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Deloitte Global is seeking a Penetration Testing Specialist to deliver comprehensive security assessments across web, API, AI/LLM, network, mobile, and thick client environments. You will provide actionable guidance to clients and contribute to the ongoing evolution of testing methodologies.

The role requires hands-on testing, strong communication, and collaboration with global teams. US citizenship is required for this position based in the United States (Tampa, FL).

Qualifications

  • Experience with Kali Linux or similar Penetration Testing OS and knowledge of common testing tools.
  • Familiarity with OWASP Top 10 weaknesses and vulnerabilities.
  • Familiarity with AI models/frameworks from Anthropic/OpenAI; experience configuring tools is a plus.
  • Working knowledge of at least one scripting language and familiarity with a programming language and framework.
  • Demonstrated experience working with diverse stakeholders, preferably globally.
  • Ability to manage concurrent initiatives with prioritization and time management.
  • Strong written and verbal communication skills.
  • Must be a US Citizen.

Responsibilities

  • Execute penetration testing engagements across web apps, APIs, AI/LLM, networks, mobile apps, and thick clients.
  • Provide consultative guidance to customers on findings in writing and verbally.
  • Enhance and update testing methodologies, processes, and standards.
  • Leverage AI/LLM tools and prompt engineering to accelerate reconnaissance and testing scripts.
  • Build, customize, and maintain AI-driven agents for recurring testing tasks.
  • Validate AI tools for accuracy and reduce false positives in vulnerability identification.
  • Evaluate integrating emerging AI-assisted offensive security tooling into team playbooks.
  • Analyze complex architecture designs and communicate capabilities to clients.
  • Collaborate with Deloitte Global teams to deliver services across borders.

Skills

Kali Linux
Burp Suite
AMASS
Metasploit
Postman
Swagger
NMAP
Qualys
SQLMap
OWASP Top 10
AI models (Anthropic/OpenAI)
Scripting
Programming basics
Global stakeholder mgmt
Time management
Communication skills
US Citizenship

Tools

Kali Linux OS
Burp Pro
AMASS
Metasploit
Postman
Swagger
NMAP
Qualys
SQLMap

Job description

Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.

Work you'll do

This role is responsible for providing penetration testing services through a combination of technology and manual ingenuity as part of the Global cyber services organization for member firms.

Responsibilities of this role include:
  • Executing Penetration testing engagements:
  • Web Application Penetration Testing
  • Web Services / Application Programming Interface (API) Penetration Testing
  • AI/LLM Penetration testing
  • Network Penetration Testing
  • Mobile Application Penetration Testing
  • Thick Client Penetration Testing
  • Providing consultative guidance to customers on findings identified in a clear and actionable fashion, both in writing and verbally
  • Enhancing and updating testing methodologies, processes, and standards documentation
  • Leveraging AI and LLM-based tools and prompt engineering, using both established platforms and emerging frameworks, to accelerate reconnaissance and generate or refine testing scripts
  • Building, customizing, and maintaining AI-driven agents to automate recurring testing tasks
  • Continuously validating the accuracy and reliability of self-developed AI tools, actively working to reduce hallucinations and false positives in vulnerability identification
  • Evaluating and integrating emerging AI-assisted offensive security tooling into team methodology and playbooks
  • Proficient at analyzing and understanding complex architecture designs.
  • Ability to effectively communicate the services and capabilities our group can facilitate to our clients.

Professionals currently in a Deloitte Global role may be considered for this position, regardless of their US location.

The team

Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.

Qualifications
Required:
  • Experienced with Kali Linux or other dedicated Penetration Testing OS Platform. With knowledge of common testing tools like Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and others
  • Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities
  • Familiarity with various AI models and frameworks from providers such as Anthropic and OpenAI, and experience configuring tools like Obsidian and Ollama is a plus for supporting other workflows.
  • Working knowledge of one scripting language and familiarity with at least one software programming language and framework
  • Demonstrated experience working with diverse stakeholders, preferably on a global multi-national basis
  • Ability to manage concurrent initiatives and use effective judgment in prioritization and time management
  • Strong written and verbal communication skills
  • Must be a US Citizen
Preferred:
  • Certified Ethical Hacker (CEH) Certification
  • Offensive Certified Security Professional (OSCP) Certification
  • Any GIAC Certification (GSEC, GWAB, GPEN, GMOB, GCPN)
  • OWASP Application Security Top 10
  • OWASP API Security Top 10
  • OWASP Thick Client Top 10
  • OWASP LLM Top 10
  • MITRE ATT&CK Framework
  • Cloud Service testing
  • Reverse Engineering
  • Static Application Software Testing (SAST)
  • Dynamic Application Testing (DAST)
  • Experience of Agentic development and its application to support penetration testing
  • Limited immigration sponsorship may be available. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Cybersecurity Jobs • Kansas City (MO)

On-site
USD 110,000 - 150,000
Penetration Tester
Penetration Tester

Cybersecurity Jobs • Nashville (TN)

On-site
USD 90,000 - 140,000
Limited immigration sponsorship may be
Penetration Tester
Penetration Tester

Cybersecurity Jobs • San Antonio (TX)

On-site
USD 90,000 - 140,000
AI-Driven Penetration Tester (Web/API/Mobile)
AI-Driven Penetration Tester (Web/API/Mobile)

Deloitte France • Tampa (FL)

On-site
USD 90,000 - 130,000
Penetration Tester
Penetration Tester

BlackHount • Bellevue (NE)

On-site
USD 70,000 - 90,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
AI-Driven Penetration Tester (Web, API, Network, AI/LLM)
AI-Driven Penetration Tester (Web, API, Network, AI/LLM)

Cybersecurity Jobs • Nashville (TN)

On-site
USD 90,000 - 140,000
Limited immigration sponsorship may be
Principal Penetration Tester
Principal Penetration Tester

Harvard Partners, LLP • Johnston (RI)

On-site
USD 120,000 - 150,000
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Penetration Tester / Ethical Hacker (Offensive Security)
Penetration Tester / Ethical Hacker (Offensive Security)

Zoho • United States

On-site
USD 83,000 - 165,000