Penetration Tester
3 months ago
Job Overview
Our client is looking for an experienced Application Penetration Tester to assess the security of a cloud-native, microservices-based architecture. You will focus on web and mobile applications, cloud security testing, adversary emulation, and continuous security improvement.
Key responsibilities include static and dynamic source code reviews using tools like SAST, DAST, and SCA. You’ll also leverage threat modeling and attack pathing to validate and enhance the organization’s security controls.
Your work will help ensure security measures function as intended and support global teams in maintaining the security of a widely used application.
Benefits
- Health Insurance: Comprehensive health insurance plans covering medical, dental, and vision.
- Competitive Salary
- 401(k) Matching
Work-Life Balance
- Generous Paid Time Off (PTO)
Professional Development
- Training and Development: Access to professional development programs, workshops, and certifications.
- Tuition Reimbursement: Financial support for further education and courses.
- Career Growth Opportunities
Company Culture
- Inclusive Environment
- Team Building Activities
Job Description
Security Testing of Developer Operations and Mobile Apps:
- Conduct thorough security testing of developer operations and mobile applications (iPhone and Android).
- Identify security issues and vulnerabilities.
Source Code Reviews:
- Perform in-depth source code reviews to identify security flaws or weaknesses.
Executing Tests/Assessments and Drafting Reports:
- Execute detailed assessments and compile findings into reports for further review and action.
Required Skills and Experience:
- Bachelor’s degree in computer science, Software Engineering, or related field, or equivalent job experience.
- Professional certifications such as GWAPT (GIAC Web Application Penetration Tester), OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), or similar.
- 3-5 years of experience in application security testing and source code review.
- Proficiency in multiple programming languages and understanding of secure coding practices.
- Strong analytical skills and attention to detail for identifying vulnerabilities.
- Testing Developer Flows and Mobile Apps: Conducts thorough security testing of developer workflows and mobile applications (for both iPhone and Android platforms), identifying security issues and vulnerabilities.
- Conducting Source Code Reviews: Performs in-depth source code reviews to identify security flaws or weaknesses that could be exploited in software applications.
- Executing Tests/Assessments and Drafting Reports: Executes detailed assessments and compiles findings into reports for further review and action.
Tools and Technologies:
Experience with tools like Burp Suite Pro, Checkmarx, Corellium, Synopsys, Acunetix, VeraCode, SAST & DAST Tools, Plextrac, Cloud security (AWS / Azure / Oracle), Postman, SmartBear ReadyAPI, SoapUI, and Hashicorp Vault
-
Cybersecurity Engineer
4 weeks ago
Washington, Washington, D.C., United States Diverse Lynx Full timeJob Title: Cybersecurity Engineer - Penetration TesterThis role involves applying security testing methodologies to identify vulnerabilities in custom solutions, ERP integrations, and commercial off-the-shelf solutions. Key responsibilities include:• Practical working knowledge of penetration testing tools and frameworks like BurpSuite, Metasploit, and...
-
Penetration Tester
2 weeks ago
Washington, United States Booz Allen Hamilton Full timeJob Number: R0211100Penetration Tester, MidKey Role:Support remote testing efforts of a client‘s network to expose weaknesses in security. Maintain baseline system security according to organizational policies. Monitor and evaluate the effectiveness of the enterprise‘s cybersecurity safeguards to ensure that they provide the intended level of protection....
-
Cloud Penetration Tester
2 days ago
Washington, Washington, D.C., United States OneZero Solutions Full timeAbout Our TeamOneZero Solutions, LLC is an employee-centric company that values team members and supports customers and missions. We pride ourselves on forward-thinking and technically proficient teams across cyber mission areas.Job ResponsibilitiesWe are seeking a Cloud Penetration Tester to perform cloud pentests and serve as the cloud pentesting SME for...
-
Penetration Tester
4 weeks ago
Washington, United States Editech Staffing Full timeJob OverviewOur client is looking for an experienced Application Penetration Tester to assess the security of a cloud-native, microservices-based architecture. You will focus on web and mobile applications, cloud security testing, adversary emulation, and continuous security improvement.Key responsibilities include static and dynamic source code reviews...
-
Lead Application Penetration Tester
4 weeks ago
Washington, United States Editech Staffing Full timeLead Application Penetration TesterOnsite / Washington, DCJob Overview Our client is seeking a highly skilled and experienced Lead Application Penetration Tester to join their dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities....
-
Penetration Tester
2 months ago
washington, United States Editech Staffing Full timeJob OverviewOur client is looking for an experienced Application Penetration Tester to assess the security of a cloud-native, microservices-based architecture. You will focus on web and mobile applications, cloud security testing, adversary emulation, and continuous security improvement.Key responsibilities include static and dynamic source code reviews...
-
Intermediate Penetration Tester
3 weeks ago
Washington, DC, United States Chenega Corporation Full timeIntermediate Penetration Tester Hybrid Schedule: In person, in the Washington, DC office twice per week Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega Military, Intelligence &...
-
Lead Application Penetration Tester
3 months ago
Washington, United States Kavaliro Full timeKavaliro is seeking an experienced Lead Application Penetration Tester to join our cyber security client. This role is perfect for someone passionate about cybersecurity and skilled in identifying and mitigating vulnerabilities in application security. As the lead, you'll be responsible for the security of cloud-native, microservices-based applications,...
-
QA Tester
3 weeks ago
Washington, United States TWO95 International Full timeTitle: QA Tester Location: Washington, DC Position: Contract Rate: $/Open Description: Test web services, web applications, APIs, mobile applications for potential vulnerabilities, Wireless penetration testing, and POS device security assessments. Run patch/configuration audit scans and create scan reports. Periodically run Host Discovery Scans, web searches...
-
QA Tester
6 months ago
Washington, United States TWO95 International Full timeTitle: QA Tester Location: Washington, DC Position: Contract Rate: $/OpenDescription:- • Test web services, web application, API, mobile application for potential vulnerabilities, Wireless penetration testing and POS device security assessments • Run patch / configuration audit scans, create scan report • Periodically run Host Discovery Scans, web...
-
Cybersecurity Consultant
2 weeks ago
Washington, United States Palo Alto Networks Full timePalo Alto Networks is seeking a seasoned cybersecurity consultant to join our team as a Principal Consultant in Offensive Security. This role offers the opportunity to work on challenging security projects, collaborate with experienced professionals, and contribute to the company's mission of creating a safer digital world.Job DescriptionWe are looking for a...
-
Senior Cybersecurity Consultant
4 weeks ago
Washington, United States Aon Full timeJob SummaryAs a Principal Security Penetration Tester at Aon, you will serve as a senior member of our penetration testing team. We are looking for motivated individuals to add to our team, providing a challenging and exciting work environment with a healthy combination of autonomy and senior-level support. Our team publishes books and security blogs,...
-
Washington, United States JPMorgan Chase & Co. Full timeAssessments & Exercises Senior Associate - Red Team OperatorContribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement.As an Assessments & Exercises Senior Associate in the Cybersecurity and Technology Controls line of business, you will contribute significantly to enhancing the firm's...
-
Lead Mobile Security Engineer
2 months ago
washington, United States Editech Staffing Full timeWe are seeking a Lead Mobile Security Engineer to join a growing team! In this role, you'll lead security testing projects, conduct in-depth code reviews, and ensure mobile applications and developer workflows are secure.Benefits IncludeHealth, Vision and Dental InsuranceGenerous Paid Time Off401K MatchingCompletion of I-9, verifying US work authorization...
-
Lead Mobile Security Engineer
5 months ago
Washington, United States Editech Staffing Full timeWe are seeking a Lead Mobile Security Engineer to join a growing team! In this role, you'll lead security testing projects, conduct in-depth code reviews, and ensure mobile applications and developer workflows are secure.Benefits IncludeHealth, Vision and Dental InsuranceGenerous Paid Time Off401K MatchingCompletion of I-9, verifying US work authorization...
-
Washington, United States Tad PGS Full timeAbout the RoleWe have an exceptional opportunity for a seasoned CyberArk Senior Systems Engineer to contribute to the success of the Department of Transportation (DOT). This Contract to Hire position offers an estimated salary range of $134,000 - $143,500 per year and comes with a wide range of benefits, including free career counseling services, 401(k), and...
-
Assessments & Exercises Director - Strategy Lead
2 weeks ago
Washington, United States JPMorgan Chase Full time $204,250 - $325,000Spearhead cutting-edge security strategies and resilience initiatives, shaping the future of cybersecurity. As an Assessments & Exercises Director in the Cyber and Tech Controls line of business, you will lead key efforts to enhance the firm's cybersecurity or resiliency posture. Plan and implement testing engagement to proactively identify risks and...
-
Assessments & Exercises Director - Strategy Lead
2 weeks ago
Washington, United States JPMorgan Chase Full time $204,250 - $325,000Spearhead cutting-edge security strategies and resilience initiatives, shaping the future of cybersecurity. As an Assessments & Exercises Director in the Cyber and Tech Controls line of business, you will lead key efforts to enhance the firm's cybersecurity or resiliency posture. Plan and implement testing engagement to proactively identify risks and...
-
Assessments & Exercises Director - Strategy Lead
3 weeks ago
Washington, DC, United States JPMorgan Chase & Co. Full timeSpearhead cutting-edge security strategies and resilience initiatives, shaping the future of cybersecurity. As an Assessments & Exercises Director in the Cyber and Tech Controls line of business, you will lead key efforts to enhance the firm's cybersecurity or resiliency posture. Plan and implement testing engagement to proactively identify risks and...
-
Washington, United States JPMorgan Chase Full time $152,000 - $260,000Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement. As an Assessments & Exercises Vice President in the Cybersecurity and Tech Controls line of business, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard...