Penetration Testing Engineer – VP

Jobtailor

Massachusetts

On-site

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jobtailor is seeking an experienced Penetration Tester to lead and execute comprehensive security assessments for web, API, and mobile apps, and manage third-party testing vendors. The role emphasizes delivering regulator-ready reports with remediation guidance and strengthening secure development practices.

Ideal candidates have 5+ years in testing across applications and networks, a track record of vendor management, and familiarity with AI/LLM-enabled testing techniques.

Qualifications

  • 5+ years in penetration testing with strong experience across both application and network testing in high-security/highly regulated environments.

Responsibilities

  • Design and manage third-party network penetration tests, including scoping, vendor selection, rules of engagement, quality assurance, and validation of results

Skills

Penetration Testing
Application Security
Network Security
Risk-Based Remediation
Vendor Management

Education

BS/MS in a relevant field
OSCP
OSEP
OSWE
GPEN
GXPN
GWAPT
PNPT
GCPN

Tools

AI/LLM Testing Techniques
Secure Development Practices
Quality Assurance

Job description

  • Design and manage third-party network penetration tests, including scoping, vendor selection, rules of engagement, quality assurance, and validation of results
  • Lead end-to-end application penetration testing across internal and third-party providers for web and API applications
  • Scope, execute, exploit, and retest application penetration tests
  • Perform advanced testing of authentication/authorization, business logic, injection, API abuse, cryptographic misuse, and access control weaknesses
  • Establish and enforce testing standards for internal teams and external vendors
  • Deliver regulator-ready reports with exploitability analysis, risk context, and actionable remediation guidance
  • Lead AI/LLM-enabled testing techniques and conduct assurance testing of enterprise AI/LLM deployments
  • Partner with engineering and infrastructure teams to validate remediation and strengthen secure development and deployment practices
  • Analyze root causes, validate fixes, and drive improvements in secure system design and implementation
Requirements
  • 5+ years in penetration testing with strong experience across both application and network testing in high-security/highly regulated environments
  • Experience managing third-party penetration testing vendors, including quality validation and outcome assurance
  • Deep expertise in application penetration testing across web, APIs, and mobile
  • Solid understanding of enterprise network attack paths
  • Strong knowledge of cloud-native architectures, microservices, identity platforms, and CI/CD pipelines
  • Ability to translate technical findings into actionable, risk-based remediation guidance and influence stakeholders
  • Experience across authentication/authorization, business logic, injection, API abuse, cryptographic misuse, and access control weaknesses
  • Experience with AI/LLM-enabled testing techniques and assurance testing of enterprise AI/LLM deployments is nice to have
  • BS/MS in a relevant field is desired, not mandatory
  • OSCP/OSEP/OSWE, GPEN/GXPN, GWAPT, PNPT, GCPN, or similar certifications are desired, not mandatory
Core Competencies

Demonstrates expertise in application and network penetration testing, with a focus on delivering actionable remediation guidance and ensuring compliance in high-security environments. Proficient in managing third-party vendors and leading advanced testing techniques, including AI/LLM-enabled assessments.

Highest-signal resume keywords
  • Penetration Testing
  • Application Security
  • Network Security
  • Risk-Based Remediation
  • Vendor Management
Hard Skills
  • Application Penetration Testing
  • Network Penetration Testing
  • API Testing
  • Authentication/Authorization Testing
  • Business Logic Testing
  • Injection Testing
  • Cryptographic Misuse Testing
  • Access Control Testing
  • Cloud-Native Architectures
  • CI/CD Pipelines
Soft Skills
  • Stakeholder Influence
  • Analytical Thinking
Certifications & Qualifications
  • OSCP
  • OSEP
  • OSWE
  • GPEN
  • GXPN
  • GWAPT
  • PNPT
  • GCPN
Industry Keywords
  • High-Security Environments
  • Regulated Environments
  • Exploitability Analysis
  • Risk Context
  • Remediation Guidance
Tools & Technologies
  • AI/LLM Testing Techniques
  • Secure Development Practices
  • Quality Assurance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Penetration Tester
Principal Penetration Tester

Harvard Partners, LLP • Johnston (RI)

On-site
USD 120,000 - 150,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Security Engineer
Security Engineer

Jobtailor • Denver (CO)

On-site
USD 140,000 - 180,000
Remote Penetration Tester
Remote Penetration Tester

Philadelphia Comapny • Atlanta (GA)

Remote
USD 80,000 - 120,000
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Senior Security Consultant (Network Penetration Tester)
Senior Security Consultant (Network Penetration Tester)

NetSPI • United States

On-site
USD 90,000 - 120,000
Senior IT Penetration Tester
Senior IT Penetration Tester

BDO USA, LLP • Oak Brook (IL)

On-site
USD 120,000 - 160,000
Lead Penetration Tester
Lead Penetration Tester

Infinite Ranges • United States

Remote
USD 138,000 - 248,000
Senior IT Penetration Tester
Senior IT Penetration Tester

BDO USA, Llp • Northern (KY)

Hybrid
USD 120,000 - 160,000
Penetration Testing Engineer II
Penetration Testing Engineer II

Jobtailor • Bentonville (AR)

On-site
USD 80,000 - 110,000