
Senior Web Application Penetration Tester
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in United States.
• Execute penetration testing on web applications, APIs, mobile apps, databases, and client-side technologies.
• Carry out application enumeration, endpoint discovery, vulnerability research, and exploitation activities.
• Recognize, validate, and evaluate vulnerabilities within intricate environments.
• Examine attack paths and security flaws to assess business and operational impacts.
• Create and use custom tools, scripts, and payloads to facilitate testing procedures.
• Conduct network mapping, vulnerability analysis, and security evaluations across applications and their supporting infrastructure.
• Investigate emerging vulnerabilities, attack techniques, and exploitation methodologies.
• Assist in post-exploitation tasks involving cloud and enterprise environments when relevant.
• Work alongside clients and internal teams to establish scope, review findings, and suggest remediation strategies.
• Articulate technical concepts and findings to both technical and non-technical stakeholders.
• Generate thorough reports that include detailed findings, exploitation processes, risk assessments, and mitigation recommendations.
• Engage in client meetings and provide continuous updates throughout assessment processes.
• Over 5 years of experience in web application penetration testing or offensive cybersecurity.
• Proven experience in performing manual web application security assessments.
• Understanding of contemporary web application vulnerabilities, attack strategies, and exploitation techniques.
• Familiarity with network mapping, vulnerability scanning, and penetration testing methodologies.
• Knowledge of NIST 800-series standards and cybersecurity best practices.
• Experience in developing scripts, payloads, or custom testing tools.
• Excellent analytical, problem-solving, and communication abilities.
• Must be eligible to obtain a Secret Clearance.
• One or more of the following offensive security certifications are highly preferred: CWES, CWEE, OSCP, OSWA, OSWE, CRTO, GWAPT, or other relevant hands-on offensive security certifications.
• Preferred experience with cloud environments, post-exploitation activities, Active Directory security assessments, FISMA compliance requirements, and working with government or regulated industry clients, as well as knowledge of common offensive security tools and frameworks.
• Employer-funded health insurance premiums (medical, dental, vision) for you and your family.
• Employer-covered short/long term disability insurance and basic life/AD&D insurance.
• 401K plan with a 4% employer contribution.
• Options for professional development reimbursement (training, certification, education, etc.).
• Flexible and remote work policies available for most positions.
• Flexible Paid Time Off (PTO) and holiday schedule.
Jumio Corporation
Moniepoint Inc. (Formerly TeamApt Inc.)
IUNA AI
TEKsystems
Get handpicked remote jobs straight to your inbox weekly.