Web Application Penetration Testing

Ampcus Inc

Chantilly (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ampcus Inc. is seeking an experienced Web Application Penetration Tester to support comprehensive security assessments of web applications, APIs, and networks.

The role requires thinking like an attacker, assessing holistically, and delivering actionable insights to enhance security of government systems. Ideal candidates have in-depth knowledge of security vulnerabilities, testing methodologies, and the ability to communicate findings with technical and executive audiences.

Qualifications

  • Bachelor’s degree in computer science, cybersecurity, information technology, or related field (or equivalent).
  • 7+ years of penetration testing experience with emphasis on web apps and APIs.
  • Knowledge of web technologies, networking, authentication, and encryption standards.
  • Strong understanding of secure development practices (SDLC) and OWASP Top 10.
  • Excellent analytical, documentation, and communication skills.

Responsibilities

  • Conduct web application, API, and network penetration tests to identify vulnerabilities.
  • Perform grey-box and black-box testing following NIST SP 800-115 and OWASP Testing Framework.
  • Evaluate authentication, session management, access controls, and data handling for flaws.
  • Execute vulnerability exploitation and proof-of-concept validation to show risk impact.
  • Document findings with precise remediation recommendations for stakeholders.
  • Collaborate with internal security engineers and client teams to verify fixes and retest.
  • Prepare comprehensive technical and executive reports that align with SEC530.
  • Support secure configuration reviews and compliance with cybersecurity standards.

Skills

Web technologies
Networking protocols
Authentication systems
Encryption standards
Secure SDLC
OWASP Top 10
Analytical skills
Documentation
Communication skills

Education

Bachelor’s degree in Computer Science / Cybersecurity

Tools

NIST SP 800-115
OWASP Testing Framework

Job description

Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.

Job Title: Web Application Penetration Testing
Location: Chantilly, VA
Position Overview
  • We are seeking an experienced and results-driven Penetration Tester to support them in performing comprehensive web application security assessments as part of the Web Application Penetration Testing opportunity.
  • The ideal candidate will have a deep understanding of web application security, vulnerability assessment, and threat exploitation methodologies. This role requires a professional who can think like an attacker, assess systems holistically, and provide actionable insights that enhance the security posture of critical government systems.
Key Responsibilities
  • Conduct web application, API, and network penetration tests to identify and validate security vulnerabilities.
  • Perform grey-box and black-box testing following NIST SP 800-115 and OWASP Testing Framework methodologies.
  • Evaluate authentication mechanisms, session management, access controls, and data handling practices for security flaws.
  • Execute vulnerability exploitation and proof-of-concept validation to demonstrate real-world risk impact.
  • Document findings with technical precision and provide clear remediation recommendations to stakeholders.
  • Collaborate with internal security engineers and client teams to verify vulnerability fixes and perform retesting.
  • Prepare and deliver comprehensive technical and executive-level reports that align with the COV Information Security Standard (SEC530).
  • Support secure configuration reviews and compliance with applicable state and federal cybersecurity standards.
Required Minimum Qualifications
  • Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent experience).
  • Preferably 7 years of experience in penetration testing or ethical hacking, with a strong focus on web applications and APIs.
  • In-depth knowledge of web technologies, networking protocols, authentication systems, and encryption standards.
  • Strong understanding of secure development practices (SDLC) and common vulnerabilities (OWASP Top 10).
  • Excellent analytical, documentation, and communication skills.
Preferred Certifications
  • CEH (Certified Ethical Hacker) - Required.
  • OSCP (Offensive Security Certified Professional) - Preferred.
  • CompTIA Security / CySA / GPEN / GWAPT - Desirable.
Desired Attributes
  • Critical thinkers with the ability to simulate real-world attacks creatively and effectively.
  • Detail-oriented with strong problem-solving and analytical skills.
  • Proactive, self-motivated, and able to manage multiple testing assignments.
  • Collaborative and professional, with the ability to work effectively in client-facing environments.
  • Strong commitment to confidentiality, ethical standards, and data security compliance.

Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veterans or individuals with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Web Application Penetration Testing
Web Application Penetration Testing

Ampcus, Inc • Chantilly (VA)

On-site
USD 80,000 - 120,000
Web App Penetration Tester | Security Assessment Expert
Web App Penetration Tester | Security Assessment Expert

Ampcus Inc • Chantilly (VA)

On-site
USD 120,000 - 160,000
Penetration Tester
Penetration Tester

OVA.Work • New York (NY)

Hybrid
USD 110,000 - 180,000
Penetration Tester
Penetration Tester

Phase2 Technology • Fort Meade (MD)

Hybrid
USD 86,000 - 198,000
Senior Penetration Testing Engineer
Senior Penetration Testing Engineer

Alliant Credit Union • Illinois

Hybrid
USD 92,000 - 145,000
Health insurance
Vision & dental
401k with employer match
+2
Penetration Tester
Penetration Tester

Booz Allen Hamilton • Fort Meade (MD)

On-site
USD 86,000 - 198,000
Health benefits
Tuition assistance
Professional development
Senior Security Test & Evaluation Analyst
Senior Security Test & Evaluation Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Senior Penetration Testing Engineer
Senior Penetration Testing Engineer

Alliant Credit Union • Chicago (IL)

Hybrid
USD 92,000 - 145,000
Annual performance bonus
Work from home up to 3 days a week
Paid parental leave
+7
Senior Penetration Tester
Senior Penetration Tester

JPMorganChase • New York (NY)

On-site
USD 120,000 - 160,000
Comprehensive health care coverage
Retirement savings plan
Tuition reimbursement