Pen Tester Job at VSG Business Solutions LLC, Westlake, OH

ZC80ams1cnVHekV0K2gweDRJZGJxdFUx
  • VSG Business Solutions LLC
  • Westlake, OH

Job Description

Job Description:


Key Responsibilities
Conduct manual and automated penetration testing of web applications, APIs, and related infrastructure.
Identify, document, and exploit security vulnerabilities such as SQL injection, cross-site scripting (XSS), authentication flaws, and business logic issues.
Perform source code reviews to identify security flaws in web applications.
Use industry-standard tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Kali Linux, and SAST/DAST tools.
Develop and execute custom scripts and exploits to validate security weaknesses.
Collaborate with development and DevSecOps teams to provide secure coding recommendations and remediation guidance.
Generate detailed reports with findings, risk assessments, and actionable remediation steps for technical and non-technical stakeholders.
Stay up to date with the latest web security trends, vulnerabilities, and attack techniques.
Perform retesting of vulnerabilities after remediation efforts.
Assist in threat modeling and risk assessments for web applications.


Tools & Technologies


The candidate should be proficient in using the following tools and technologies for web application penetration testing:


Web Application Security Testing Tools:
Burp Suite (Pro & Community)
WebInspect
Network & Reconnaissance Tools:
Nmap
Masscan
Amass
Subfinder / Assetfinder
Shodan / Censys
Exploitation & Attack Tools:
SQLmap (SQL injection testing), Metasploit Framework,
Scripting & Automation:
Python / Bash / PowerShell
JavaScript (for DOM-based attacks and exploitation)
Postman / REST API testing tools
Code Analysis & Debugging:
Source Code Review (Java, .NET, Python, JavaScript, etc.)
Static Analysis Tools (SAST) SonarQube, Snyk, Fortify
Dynamic Analysis Tools (DAST): Acunetix,


Cloud & Container Security:
AWS Security Tools (Pacu, ScoutSuite, Prowler)
Docker Security Testing (Trivy, Dockle)
Kubernetes Security Testing (Kube-hunter, Kube-bench)


Qualifications & Skills
Technical Skills:
Deep understanding of OWASP Top 10 vulnerabilities and web security principles.
Proficiency in protocols, authentication mechanisms, session management, and API security.
Experience with scripting (Python, Bash, PowerShell, JavaScript) for automation and exploit development.
Familiarity with Cloud Security (AWS, Azure, GCP) and container security (Docker, Kubernetes) is a plus.
Knowledge of Secure Software Development Life Cycle (SDLC) practices.
Certifications (Preferred but Not Required):
OSCP (Offensive Security Certified Professional)
GWAPT (GIAC Web Application Penetration Tester)
CPT (Certified Penetration Tester)
CEH (Certified Ethical Hacker)
Experience & Education:
Bachelor's degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
2-5 years of experience in web application security, penetration testing, or ethical hacking




Job Tags

Similar Jobs

Aspira Connect

Sr. Director of Information Security Job at Aspira Connect

 ...Sr. Director, Information Security Aspira | IT Operations About Aspira For more than 40 years, Aspira has been the market-leading provider of software and services that help public agencies protect natural and cultural resources while making them accessible for... 

GearUp2Success

Senior Leadership Coach Job at GearUp2Success

 ...Work from anywhere | Leadership Industry | Flexible & Self-Paced Coaches: Ready to Transition into a More Rewarding Career? Are you an experienced Leadership Coach looking for greater freedom, income potential, and personal growth? If youre passionate about leadership... 

Lambda

Remote Account CTO Job at Lambda

Lambda, The Superintelligence Cloud, builds Gigawatt-scale AI Factories for Training and Inference. Lambdas mission is to make compute as ubiquitous as electricity and give every person access to artificial intelligence. One person, one GPU. If youd like to build the...

Tepuy Donuts

Wholesale Sales Manager Job at Tepuy Donuts

 ...Wholesale Sales Manager - Highly Skilled Are you passionate about the Food & Beverage industry and thrive in a dynamic sales environment...  ...local businesses, retailers, and hospitality partners Drive B2B sales by introducing our products to new wholesale accounts Coordinate... 

Apple

Wireless Firmware Engineer Job at Apple

Wireless Firmware Engineer Location San Diego, CA : Summary Posted: May 3, 2025 Role Number: 200451271 At Apple, new way of thinking and insights can turn in to extraordinary products very quickly. The success we are striving will be result of highly skilled team working...