Pen Tester Job at VSG Business Solutions LLC, Westlake, OH

ZC80ams1cnVHekV0K2gweDRJZGJxdFUx
  • VSG Business Solutions LLC
  • Westlake, OH

Job Description

Job Description:


Key Responsibilities
Conduct manual and automated penetration testing of web applications, APIs, and related infrastructure.
Identify, document, and exploit security vulnerabilities such as SQL injection, cross-site scripting (XSS), authentication flaws, and business logic issues.
Perform source code reviews to identify security flaws in web applications.
Use industry-standard tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Kali Linux, and SAST/DAST tools.
Develop and execute custom scripts and exploits to validate security weaknesses.
Collaborate with development and DevSecOps teams to provide secure coding recommendations and remediation guidance.
Generate detailed reports with findings, risk assessments, and actionable remediation steps for technical and non-technical stakeholders.
Stay up to date with the latest web security trends, vulnerabilities, and attack techniques.
Perform retesting of vulnerabilities after remediation efforts.
Assist in threat modeling and risk assessments for web applications.


Tools & Technologies


The candidate should be proficient in using the following tools and technologies for web application penetration testing:


Web Application Security Testing Tools:
Burp Suite (Pro & Community)
WebInspect
Network & Reconnaissance Tools:
Nmap
Masscan
Amass
Subfinder / Assetfinder
Shodan / Censys
Exploitation & Attack Tools:
SQLmap (SQL injection testing), Metasploit Framework,
Scripting & Automation:
Python / Bash / PowerShell
JavaScript (for DOM-based attacks and exploitation)
Postman / REST API testing tools
Code Analysis & Debugging:
Source Code Review (Java, .NET, Python, JavaScript, etc.)
Static Analysis Tools (SAST) SonarQube, Snyk, Fortify
Dynamic Analysis Tools (DAST): Acunetix,


Cloud & Container Security:
AWS Security Tools (Pacu, ScoutSuite, Prowler)
Docker Security Testing (Trivy, Dockle)
Kubernetes Security Testing (Kube-hunter, Kube-bench)


Qualifications & Skills
Technical Skills:
Deep understanding of OWASP Top 10 vulnerabilities and web security principles.
Proficiency in protocols, authentication mechanisms, session management, and API security.
Experience with scripting (Python, Bash, PowerShell, JavaScript) for automation and exploit development.
Familiarity with Cloud Security (AWS, Azure, GCP) and container security (Docker, Kubernetes) is a plus.
Knowledge of Secure Software Development Life Cycle (SDLC) practices.
Certifications (Preferred but Not Required):
OSCP (Offensive Security Certified Professional)
GWAPT (GIAC Web Application Penetration Tester)
CPT (Certified Penetration Tester)
CEH (Certified Ethical Hacker)
Experience & Education:
Bachelor's degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
2-5 years of experience in web application security, penetration testing, or ethical hacking




Job Tags

Similar Jobs

Armed Services YMCA of The U S A

Lifeguard Year Round or Summer Job at Armed Services YMCA of The U S A

 ...position routinely works at an indoor swimming facility. During summer months only outdoor weather conditions with little to no...  ...Work Location : One location Job Type: Part-time Temporary (Summer) Salary: $15.00 - $17.00 per hour Benefits: ~4... 

Catholic Health Initiatives

Student Nurse Tech Job at Catholic Health Initiatives

**Job Summary and Responsibilities**CHI St. Alexius is looking for Student Nurse Techs to join the team!Are you a compassionate and dedicated individual eager to support patients in their healthcare journey? We're seeking Student Nurse Techs to join our dynamic nursing... 

NPL Construction Co.

Natural Gas Relight Technician Job at NPL Construction Co.

 ...Who We Are At NPL, we build and maintain natural gas infrastructure that keeps communities running. Were currently hiring Plumbers and Natural Gas Relight Technicians to join our construction crews. These roles are critical in safely installing, maintaining, and... 

Enloe Health

Helicopter Pilot at Enloe Health Job at Enloe Health

 ...purpose, we welcome you to join our team. POSITION SUMMARY: Using technical and communication skills, and as a team player, the Pilot is responsible for operating the helicopter in a safe, efficient manner. Pilots will be qualified in the Airbus H125 and H130.... 

Kinross Gold Corporation

Mine Geologist Job at Kinross Gold Corporation

 ...Alaska being developed with ore being hauled to Kinross Fort Knox mine north of Fairbanks for processing. The mine site is located in...  ...Responsible for the timely integration of geologic and blasthole data into grade control ore releases guiding open-pit operations. Responsible...