Job Description
Job Description:
Key Responsibilities
Conduct manual and automated penetration testing of web applications, APIs, and related infrastructure.
Identify, document, and exploit security vulnerabilities such as SQL injection, cross-site scripting (XSS), authentication flaws, and business logic issues.
Perform source code reviews to identify security flaws in web applications.
Use industry-standard tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Kali Linux, and SAST/DAST tools.
Develop and execute custom scripts and exploits to validate security weaknesses.
Collaborate with development and DevSecOps teams to provide secure coding recommendations and remediation guidance.
Generate detailed reports with findings, risk assessments, and actionable remediation steps for technical and non-technical stakeholders.
Stay up to date with the latest web security trends, vulnerabilities, and attack techniques.
Perform retesting of vulnerabilities after remediation efforts.
Assist in threat modeling and risk assessments for web applications.
Tools & Technologies
The candidate should be proficient in using the following tools and technologies for web application penetration testing:
Web Application Security Testing Tools:
Burp Suite (Pro & Community)
WebInspect
Network & Reconnaissance Tools:
Nmap
Masscan
Amass
Subfinder / Assetfinder
Shodan / Censys
Exploitation & Attack Tools:
SQLmap (SQL injection testing), Metasploit Framework,
Scripting & Automation:
Python / Bash / PowerShell
JavaScript (for DOM-based attacks and exploitation)
Postman / REST API testing tools
Code Analysis & Debugging:
Source Code Review (Java, .NET, Python, JavaScript, etc.)
Static Analysis Tools (SAST) SonarQube, Snyk, Fortify
Dynamic Analysis Tools (DAST): Acunetix,
Cloud & Container Security:
AWS Security Tools (Pacu, ScoutSuite, Prowler)
Docker Security Testing (Trivy, Dockle)
Kubernetes Security Testing (Kube-hunter, Kube-bench)
Qualifications & Skills
Technical Skills:
Deep understanding of OWASP Top 10 vulnerabilities and web security principles.
Proficiency in protocols, authentication mechanisms, session management, and API security.
Experience with scripting (Python, Bash, PowerShell, JavaScript) for automation and exploit development.
Familiarity with Cloud Security (AWS, Azure, GCP) and container security (Docker, Kubernetes) is a plus.
Knowledge of Secure Software Development Life Cycle (SDLC) practices.
Certifications (Preferred but Not Required):
OSCP (Offensive Security Certified Professional)
GWAPT (GIAC Web Application Penetration Tester)
CPT (Certified Penetration Tester)
CEH (Certified Ethical Hacker)
Experience & Education:
Bachelor's degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
2-5 years of experience in web application security, penetration testing, or ethical hacking
Job Tags
Similar Jobs
State of Missouri
...Working with the Division of Youth Services is more than it seems. You will be working with staff to create a safe, therapeutic, and educational environment for youth in our day treatment and residential programs. To succeed in this position you will need to be empathetic,...
Hilton Garden Inn Morgantown
...shopping and dining. It is also just minutes away from Ruby Memorial Hospital, West Virginia University, Mountaineer Field and the WVU... ...Housekeeper at The Hilton Garden Inn, you will be responsible for cleaning and supplying all daily assigned rooms and to report all damage...
Edgewell Personal Care Brands, LLC
...and celebrate our shared achievements. This role is Hybrid out of either our NYC or Shelton, CT office Associate Brand Manager, Jack Black Grooming Strategy Position Summary The Associate Brand Manager will be an integral member of the Jack Black Brand...
Ottumwa Regional Health Center
...Registered Nurse (RN), PACU Job Type: Full-Time Day Shift 0700 or 0730 -1800 | 4-10 Shifts and weekend rotation every 4 weeks Commitment Bonus of $15,000 (2 years) Who We Are: People are our passion and purpose. Come work where you are appreciated for who you...
US Bureau of Land Management
...Clarification from the agency All U.S. Citizens - No previous federal service is required. This position is being advertised under an OPM government-wide Direct Hire authority. CTAP and ICTAP candidates in the local commuting area. Duties Advises leadership...