Security Assurance Penetration Tester

Jobtailor

Connecticut

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in the United States seeks a security-focused penetration tester to assess web apps, APIs, and cloud services. You will identify vulnerabilities, collaborate with development teams, and drive remediation across GenAI integrations and traditional applications.

Ideal candidates have certifications and hands-on testing experience with Burp Suite, Nmap, Metasploit, and Nuclei, plus scripting in Python or PowerShell. This is a full-time on-site role in Connecticut.

Qualifications

  • Experience in information security, penetration testing, or related field.
  • Experience or coursework in software development, DevOps, or scripting is highly desirable.
  • Security certifications such as Security+, CEH, PNPT, OSCP preferred.
  • Foundational understanding of web app architecture, networking, and OS security.
  • Familiarity with penetration testing tools (Burp Suite, Nmap, Metasploit, Nuclei).
  • Working knowledge of OWASP Top 10, CVSS.
  • Scripting in Python, Bash, PowerShell, or similar.
  • Cloud knowledge (AWS, Azure, GCP) and security considerations.
  • Exposure to SAST/DAST and secure code review practices.
  • Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations).

Responsibilities

  • Track findings from assessments and ensure timely remediation.
  • Collaborate with development, platform, and product teams to communicate findings and track remediation.
  • Facilitate post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues.
  • Maintain program documentation, test records, and reporting artifacts.
  • Conduct penetration testing of web applications, APIs, cloud environments, and internal systems; escalate complex testing scenarios as needed.
  • Perform peer review of penetration testing deliverables, including test plans, findings, and final reports.
  • Participate in scoping exercises and contribute to testing methodologies.
  • Support security assessments of GenAI-powered applications and features, including LLM integrations and RAG pipelines.
  • Assist in testing for AI-specific vulnerabilities such as prompt injection and data leakage.
  • Contribute to GenAI security testing checklists and ensure alignment with OWASP Top 10 for LLMs.

Skills

Penetration testing
Web application security
Cloud security
Scripting (Python/PowerShell)
OWASP Top 10
CVSS

Education

Information security certification
Cybersecurity degree

Tools

Burp Suite
Nmap
Metasploit
Nuclei

Job description

Responsibilities
  • Tracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking.
  • Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture.
  • Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.
  • Maintaining program documentation, test records, and reporting artifacts.
  • Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.
  • Performing peer review of penetration testing deliverables, including test plans, findings, and final reports.
  • Participating in scoping exercises and contributing to the selection of appropriate testing methodologies.
  • Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
  • Assisting in testing for AI‑specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.
  • Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs.
Requirements
  • Experience in information security, penetration testing, or a related field.
  • Experience or coursework in software development, DevOps, or scripting is highly desirable.
  • At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.
  • Foundational understanding of web application architecture, networking, and operating system security.
  • Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).
  • Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).
  • Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.
  • Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations.
  • Exposure to SAST/DAST tools and secure code review practices is desirable.
  • Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations).
Core Competencies

Demonstrates expertise in penetration testing, security assessments, and remediation tracking, with a strong foundation in web application architecture and cloud security. Proficient in scripting and familiar with security frameworks and methodologies relevant to GenAI applications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GenAI Security Penetration Tester
GenAI Security Penetration Tester

RXinsider LTD. • Northern (KY)

Hybrid
USD 72,000 - 119,000
Senior Security Testing Specialist – Application Security
Senior Security Testing Specialist – Application Security

Jobtailor • Arizona

On-site
USD 90,000 - 130,000
Senior AI DevSecOps Engineer
Senior AI DevSecOps Engineer

Jobtailor • Kansas

On-site
USD 120,000 - 180,000
Senior Security Engineer – Penetration Tester
Senior Security Engineer – Penetration Tester

Jobtailor • North Carolina

On-site
USD 120,000 - 190,000
AI Security Engineer AI Security Unit
AI Security Engineer AI Security Unit

Check Point Software Technologies • Washington

On-site
USD 135,000 - 195,000
Engineering, Cybersecurity, Application Security Engineer, Vice President
Engineering, Cybersecurity, Application Security Engineer, Vice President

TPG Careers Page • Fort Worth (TX)

On-site
USD 230,000 - 320,000
Principal Engineer – Secure AI
Principal Engineer – Secure AI

Jobtailor • Brooklyn Park (MN)

On-site
USD 150,000 - 230,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Senior Lead AI Security Engineer
Senior Lead AI Security Engineer

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 120,000 - 150,000
IT Security Analyst
IT Security Analyst

Fortegra • Jacksonville (FL)

On-site
USD 85,000 - 120,000