Security Engineer

Dahl Consulting

Minneapolis (MN)

Hybrid

USD 103,000 - 135,000

Full time

14 days+
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Dahl Consulting is seeking a Security Engineer for a 12-month contract to bolster security for high-traffic web applications, APIs, and enterprise systems. You will perform end-to-end penetration testing with a hands-on, offensive-security approach in a mature security organization.

Responsibilities include scoping, exploiting, and validating findings, delivering actionable remediation guidance, and mentoring engineers. Strong experience with Burp Suite and scripting in Python or Go is required.

Qualifications

  • 5+ years of hands-on penetration testing experience in enterprise environments.
  • End-to-end penetration testing experience (scoping, exploitation, validation, reporting).
  • Strong knowledge of web vulnerabilities (OWASP Top 10, auth flaws, injection).
  • Proficiency with Burp Suite, Nmap, and exploitation frameworks.
  • Experience writing scripts in Python or Go to support testing workflows.

Responsibilities

  • Plan and execute full-lifecycle penetration tests across web apps, APIs, and infrastructure.
  • Assess vulnerabilities and provide actionable remediation guidance to engineering teams.
  • Automate and mature offensive security capabilities through tooling and threat modeling.
  • Collaborate with engineering to validate fixes and ensure vulnerabilities are remediated.

Skills

Penetration testing
Web applications & APIs
Python or Go scripting
Burp Suite
Nmap
Threat modeling
Documentation of findings

Education

Bachelor's degree in Computer Science or Cybersecurity

Tools

Burp Suite
Nmap
Common exploitation frameworks

Job description

Security Engineer

Location: Remote

Job Type: Contract (12 Months)

Compensation: $75.19 - $97.74/hr

About the Role

On behalf of our client - a leading national retailer with a large-scale digital and e-commerce presence - we are seeking an experienced Security Engineer to strengthen the security posture of high-traffic web applications, APIs, and enterprise systems. This role sits within a mature security organization that protects millions of customers and safeguards sensitive payment and personal data across a complex, high-volume environment. You'll take a hands-on, offensive-security approach, identifying and validating vulnerabilities before they can be exploited, and partnering closely with engineering teams to drive meaningful remediation. This is an excellent opportunity for a seasoned penetration tester who thrives in enterprise-scale environments, enjoys deep technical work, and wants to make a direct impact on the security of widely used consumer-facing platforms.

Job Description

As a Security Engineer, you will lead end-to-end penetration testing engagements across web applications, APIs, and supporting infrastructure. You will scope assessments, execute exploitation and validation, and deliver clear, actionable findings that engineering teams can act on. Beyond individual testing, you'll help mature the organization's offensive security capabilities through automation, threat modeling, and technical mentorship.

Key Responsibilities
  • Planning and executing full-lifecycle penetration tests, including scoping, exploitation, validation, and reporting.
  • Assessing web applications and APIs for vulnerabilities, with a focus on the OWASP Top 10, authentication/authorization flaws, and injection attacks.
  • Leveraging core security tooling - including advanced use of Burp Suite, Nmap, and common exploitation frameworks - to uncover and confirm risks.
  • Developing scripts and automations in Python or Go to streamline and scale testing workflows.
  • Documenting findings clearly and providing actionable remediation guidance to engineering partners.
  • Collaborating with engineering teams to validate fixes and confirm vulnerabilities are fully remediated.
  • Identifying risk areas early through threat modeling and pre-deployment review.
Qualifications Required
  • 5+ years of hands-on penetration testing experience, focused on web applications and APIs in enterprise environments.
  • Demonstrated experience executing end-to-end penetration tests (scoping, exploitation, validation, and reporting).
  • Strong working knowledge of web application vulnerabilities, including the OWASP Top 10, authentication/authorization flaws, and injection attacks.
  • Proficiency with core security testing tools, including: Burp Suite (advanced usage required), Nmap, Common exploitation frameworks.
  • Experience writing scripts or automations in Python or Go to support testing workflows.
  • Ability to clearly document findings with actionable remediation guidance for engineering teams.
  • Experience partnering with engineering teams to validate and remediate vulnerabilities.
  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent practical experience.
  • 7+ years in cybersecurity, with demonstrated progression in penetration testing responsibilities.
Preferred Qualifications
  • Experience testing mobile applications, hardware/embedded systems, or third-party/vendor platforms.
  • Familiarity with PCI-related penetration testing requirements and compliance contexts.
  • Experience contributing to or supporting bug bounty programs (triage, validation, and escalation).
  • Exposure to threat modeling and the ability to identify risk areas pre-deployment.
  • Experience mentoring or providing technical guidance to other testers.
  • Advanced understanding of networking and system architecture in large-scale environments.
  • Experience improving or automating penetration testing processes and tooling.
  • Relevant certifications such as OSCP, OSCE, OSWE, or CISSP.
Benefits

Dahl Consulting is proud to offer a comprehensive benefits package to eligible employees that will allow you to choose the best coverage to meet your family’s needs. For details, please review the DAHL Benefits Summary: https://www.dahlconsulting.com/benefits-w2fta/.

Equal Opportunity Statement

As an equal opportunity employer, Dahl Consulting welcomes candidates of all backgrounds and experiences to apply.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Penetration Testing Engineer (Security)
Remote Penetration Testing Engineer (Security)

Dahl Consulting • Minneapolis (MN)

Hybrid
USD 103,000 - 135,000
Application Security Consultant
Application Security Consultant

Direct Defense • Englewood (CO)

On-site
USD 100,000 - 108,000
401(k)
AD&D Insurance
Dental Insurance
+6
Application Security Consultant
Application Security Consultant

Direct Defense • Northern (KY)

Hybrid
USD 96,000 - 124,000
Senior Penetration Tester – Application Security
Senior Penetration Tester – Application Security

ITR Group • Minneapolis (MN)

On-site
USD 110,000 - 124,000
Offensive Security & Code Analysis Engineer
Offensive Security & Code Analysis Engineer

Districttechgroup • Washington

Hybrid
USD 80,000 - 120,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+1
Security VAPT Engineer
Security VAPT Engineer

Salt Digital Recruitment • Chicago (IL)

Hybrid
USD 120,000 - 160,000
Penetration Tester
Penetration Tester

Darkwolfsolutions • Colorado Springs (CO)

On-site
USD 130,000 - 145,000
Application Security Engineer
Application Security Engineer

Droisys • Dallas (TX)

On-site
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI Inc. • Minneapolis (MN)

On-site
USD 110,000 - 150,000
Senior Security Engineer (Penetration Testing/GRC Assessments)
Senior Security Engineer (Penetration Testing/GRC Assessments)

Structured Communication Systems Inc • Washington

Remote
USD 110,000 - 130,000
Medical, dental, and vision insurance
401(k)
Paid training