Senior Penetration Tester – Application Security

ITR Group

Minneapolis (MN)

On-site

USD 110,000 - 124,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

ITR Group is seeking a Senior Penetration Tester to lead hands-on testing of web applications and APIs in enterprise environments. The role requires independent management of engagements from scoping through reporting and remediation validation.

The candidate should have advanced Burp Suite experience and at least 5+ years of hands-on testing. Strong scripting skills (Python/Go) and collaboration with engineering teams are essential.

Qualifications

  • 5+ years of hands-on penetration testing experience.
  • Strong web application and API penetration testing experience.
  • Experience independently executing end-to-end penetration tests.
  • Strong understanding of application vulnerabilities.
  • Advanced Burp Suite experience.
  • Experience with Nmap and exploitation frameworks.
  • Python or Go scripting/automation experience.
  • Strong technical documentation and communication skills.
  • Experience working directly with engineering teams on remediation.

Responsibilities

  • Execute end-to-end penetration tests, including scoping, exploitation, validation, reporting, and remediation support.
  • Perform web application and API security testing.
  • Identify and evaluate OWASP Top 10 and other application vulnerabilities.
  • Assess authentication, authorization, injection, and other security weaknesses.
  • Use Burp Suite, Nmap, and common exploitation frameworks.
  • Develop Python or Go scripts and automation to support testing workflows.
  • Document findings with actionable remediation guidance.
  • Partner with engineering teams to validate and remediate vulnerabilities.
  • Contribute to improving penetration testing processes and tooling.

Skills

Penetration testing
Web app testing
API testing
Burp Suite
Nmap
Exploitation frameworks
Python scripting
Go scripting
Documentation
Engineering collaboration

Education

Bachelor's degree in CS/Cybersecurity
7+ years cybersecurity experience

Tools

Burp Suite
Nmap

Job description

Opportunity available for a Senior Penetration Tester with strong hands‑on experience testing web applications and APIs in enterprise environments. The ideal candidate will have advanced Burp Suite experience and the ability to independently manage penetration testing engagements from scoping through reporting and remediation validation.

Key Responsibilities
  • Execute end-to-end penetration tests, including scoping, exploitation, validation, reporting, and remediation support
  • Perform web application and API security testing
  • Identify and evaluate OWASP Top 10 and other application vulnerabilities
  • Assess authentication, authorization, injection, and other security weaknesses
  • Use Burp Suite, Nmap, and common exploitation frameworks
  • Develop Python or Go scripts and automation to support testing workflows
  • Document findings with actionable remediation guidance
  • Partner with engineering teams to validate and remediate vulnerabilities
  • Contribute to improving penetration testing processes and tooling
Required Skills
  • 5+ years of hands‑on penetration testing experience
  • Strong web application and API penetration testing experience
  • Experience independently executing end-to-end penetration tests
  • Strong understanding of application vulnerabilities
  • Advanced Burp Suite experience
  • Experience with Nmap and exploitation frameworks
  • Python or Go scripting/automation experience
  • Strong technical documentation and communication skills
  • Experience working directly with engineering teams on remediation
Strongly Preferred
  • PCI penetration testing experience
  • Mobile application, hardware/embedded systems, or third‑party/vendor platform testing
  • Bug bounty triage and validation experience
  • Threat modeling experience
  • Mentoring or technical guidance experience
Nice to Have
  • Advanced networking and system architecture knowledge
  • Penetration testing automation/process improvement experience
  • OSCP, OSCE, OSWE, CISSP, or similar certifications
Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent practical experience
  • 7+ years of cybersecurity experience, with progressive penetration testing responsibilities
Important:

Important: This is a W-2 opportunity only — no C2C.

ITR Group offers a competitive compensation and benefits package, including medical, dental, and 401(k) for eligible employees. The pay rate for this role is approximately 80-90 hourly. This range is an estimate and not a guarantee of compensation. The final compensation will be determined by factors such as experience, market trends, and specific job assignments. Discover more about how ITR Group connects top talent with leading client opportunities.

ITR Group is an Equal Opportunity Employer. We do not discriminate against applicants on the basis of their race, color, national origin, religion, creed, disability, age, sex, sexual orientation, gender identity, marital status, familial status, or status with regard to public assistance, or membership or activity in a local human rights commission.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Web & API Penetration Tester
Senior Web & API Penetration Tester

ITR Group • Minneapolis (MN)

On-site
USD 110,000 - 124,000
Penetration Tester
Penetration Tester

Ringside Talent • Columbus (OH)

Hybrid
USD 90,000 - 130,000
OSCP/GPEN sponsorship
Hands-on security culture
Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Principal Penetration Tester
Principal Penetration Tester

Harvard Partners, LLP • Johnston (RI)

On-site
USD 120,000 - 150,000
Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 90,000 - 120,000
Senior Application Security Engineer
Senior Application Security Engineer

Signature IT World Inc • New York (NY)

On-site
USD 100,000 - 150,000
Penetration Tester
Penetration Tester

Darkwolfsolutions • Colorado Springs (CO)

On-site
USD 130,000 - 145,000
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Penetration Tester
Penetration Tester

Dark Wolf Solutions • Colorado Springs (CO)

Hybrid
USD 130,000 - 145,000
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 90,000 - 130,000