
Penetration Tester
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in Florida.
• Execute penetration testing for web applications, mobile applications, thick clients, and APIs.
• Carry out source code reviews and whitebox penetration testing to demonstrate the impact of application vulnerabilities.
• Reverse engineer mobile and thick client applications.
• Integrate application vulnerabilities into cloud and on-premises Active Directory environments when relevant.
• Generate comprehensive reports on discoveries and remediation strategies for significant findings.
• Present findings to both technical and executive audiences.
• Conduct SAST and DAST assessments on enterprise, SaaS, and custom in-house applications.
• Utilize scanners to validate findings while minimizing false positives.
• Strong working knowledge of C, C#, Python, Objective-C, Java, JavaScript, SQL, and AngularJS.
• Familiarity with XML, JSON, SOAP, REST, and AJAX.
• Insight into AI/LLM vulnerabilities and application flaws.
• Extensive experience with an attack proxy like Burp Suite.
• Preferably 3–5 years of experience in penetration testing and consulting.
• A minimum of two years in information security-related roles.
• Possession of professional certifications such as OSCP, OSWE, or BSCP.
• OSCP or Burp certification is mandatory for the organization.
• Must reside in Florida.
• Profound understanding of OWASP guidelines for Web, API, Mobile, and AI/LLM.
• Skilled developer/application security tester.
• Competitive salary and performance-based pay.
• Opportunities for employee growth and development.
• Fully remote position (within Florida).
Abhyaz
Commence
Isenberg & Hewitt, P.C.
CCR GROUP
Get handpicked remote jobs straight to your inbox weekly.