Principal Consultant

AGS

United States

On-site

USD 100,000 - 130,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

A leading cybersecurity consulting firm is seeking a Principal AppSec Penetration Testing Consultant to lead complex security assessments. This role demands a hands-on expert with over 5 years of experience in application penetration testing, proficiency in SAST and DAST tools, and strong communication skills. Responsibilities include delivering comprehensive pen tests, producing detailed reports, and mentoring junior staff. The position is full-time and suits those with a passion for security and technical excellence.

Qualifications

  • 5+ years of experience in application penetration testing.
  • Strong understanding of SAST and DAST tools and workflows.
  • Excellent written and verbal communication skills.

Responsibilities

  • Lead and perform advanced application penetration tests.
  • Design and execute manual and automated testing approaches.
  • Produce clear, professional penetration test reports.

Skills

Application penetration testing
SAST and DAST understanding
Secure development practices
Communication with stakeholders

Job description

Principal AppSec Penetration Testing Consultant

We are seeking a highly experienced Principal AppSec Penetration Testing Consultant to lead and deliver complex security assessments across a wide range of environments. This role suits a hands‑on expert who enjoys deep technical work while also owning delivery quality, mentoring others, and acting as a trusted security advisor to clients.

Key Responsibilities
  • Lead and perform advanced application penetration tests across modern web technologies, frameworks, APIs, and microservice‑based architectures.
  • Design and execute manual and automated testing approaches, incorporating SAST and DAST methodologies to complement hands‑on exploitation and maximise coverage.
  • Deliver high‑quality Pentesting beyond web applications, including network, cloud security, mobile app, red team engagements, and social engineering where appropriate.
  • Own engagements end to end, from scoping and threat modelling through execution, reporting, and final client presentations.
  • Produce clear, professional penetration test reports with actionable remediation guidance, suitable for engineers, security teams, and senior stakeholders.
  • Present findings to both technical and non‑technical audiences, translating vulnerabilities into business‑relevant risk and prioritised recommendations.
  • Act as a senior technical authority, contributing to methodology development, quality assurance, and mentoring of junior consultants.
  • Stay current with emerging vulnerabilities, attack techniques, and tooling, including developments in secure SDLC, SAST, and DAST practices.
Required Skills & Experience
  • 5+ years of experience performing complex application penetration tests across common web technologies and application stacks.
  • Strong understanding of SAST and DAST tools and workflows, including how to interpret results, reduce false positives, and integrate findings into manual testing.
  • Broad technical skillset enabling delivery of high‑quality security assessments across multiple domains, not limited to AppSec.
  • Solid knowledge of secure development practices, common vulnerability classes (e.g. OWASP Top 10), and real‑world exploitation techniques.
  • Experience leading penetration tests from scoping to final delivery in a consulting environment.
  • Excellent written and verbal communication skills, with the ability to communicate effectively with both technical and non‑technical stakeholders.
Nice to Have
  • Industry‑recognised certifications such as OSCP, OSCE, OSWA, OSWE, CRTO, BSCP, or equivalent.
  • Published security research, CVEs, blog posts, conference talks, or open‑source security tools.
  • Active involvement in CTFs, bug bounty programmes, security research, or the wider hacking community.
  • Completion of relevant security‑related MOOCs, training programmes, or recognised books.
Seniority level

Mid‑Senior level

Employment type

Full‑time

Job function

Consulting

Industries

Computer and Network Security and IT Services and IT Consulting

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead AppSec Penetration Testing Consultant
Lead AppSec Penetration Testing Consultant

AGS • United States

On-site
USD 100,000 - 130,000
Principal Penetration Tester
Principal Penetration Tester

Harvard Partners, LLP • Johnston (RI)

On-site
USD 120,000 - 150,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Remote Penetration Tester
Remote Penetration Tester

Philadelphia Comapny • Atlanta (GA)

Remote
USD 80,000 - 120,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Principal Security Consultant (Hardware/Embedded Penetration Tester)
Principal Security Consultant (Hardware/Embedded Penetration Tester)

NetSPI Inc. • Minneapolis (MN)

On-site
USD 100,000 - 130,000
Offensive Security Consultant
Offensive Security Consultant

Konica Minolta Business Solutions Canada • Kansas City (MO)

On-site
USD 80,000 - 100,000
Application Offensive Security Consultant
Application Offensive Security Consultant

Pipe Recruit • Jersey City (NJ)

Hybrid
USD 83,000 - 165,000
Offensive Security Consultant / Penetration Tester
Offensive Security Consultant / Penetration Tester

HALOCK Security Labs • Schaumburg (IL)

On-site
USD 120,000 - 180,000