
Penetration Tester
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Australia.
• Carry out penetration testing for web applications, mobile applications, thick clients, and APIs.
• Execute source code reviews and whitebox penetration testing to demonstrate the impact of application vulnerabilities.
• Reverse engineer mobile and thick client applications.
• Integrate application vulnerabilities into cloud and on-premises Active Directory systems.
• Create comprehensive reports detailing findings and recommendations for significant issues.
• Acquire skills to present findings to both technical and executive audiences.
• Conduct SAST and DAST on enterprise, SaaS, and custom in-house applications.
• Utilize scanners to assess vulnerabilities and validate or dismiss false positives.
• May explore limited lateral movement into infrastructure teams at the discretion of the manager.
• Experienced developer or application security tester.
• Strong working knowledge of C, C#, Python, Objective-C, Java, JavaScript, SQL, and AngularJS.
• Familiarity with XML, JSON, SOAP, REST, and AJAX.
• Insight into AI/LLM vulnerabilities and flaws within applications.
• Significant experience and expertise with an attack proxy like Burp Suite.
• Preferred: 3–5 years of experience in penetration testing and consulting.
• Graduate of a post-secondary college or university program.
• Minimum of two years of experience in information security-related roles.
• Professional qualifications, including one or more of OSCP, OSWE, BSCP.
• OSCP or Burp certification is mandatory for the organization.
• Strong understanding of OWASP principles in Web, API, Mobile, and AI/LLM contexts.
• Experience with scanners, including knowledge of validating and eliminating false positives.
• Availability to work initial after-hours schedules aligned with the Eastern Time Zone (Canada/US) team.
• Initial onboarding and collaboration may require after-hours work, with flexible scheduling as the role transitions to regular local hours.
• Immediate and ongoing offensive security training.
• Competitive compensation.
• Opportunities for growth.
• A fantastic team and working environment.
Paradigm Information Services, Inc.
Latitude IT Solutions | SDVOSB
ICF
v4c.ai
Get handpicked remote jobs straight to your inbox weekly.