Lead Application Penetration Tester
3 weeks ago
Job Overview
Our client is seeking a highly skilled and experienced Lead Application Penetration Tester to join their dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful candidate will play a critical role in ensuring the security of our applications and guiding our security testing and vulnerability triage.
As a lead, you will oversee a comprehensive security assessment of a cloud-native, microservices-based architecture. Your focus will be on web and mobile applications, cloud security testing, adversary emulation, and continuous security posture improvement. You will mentor junior team members and lead the development of security strategies and best practices.
You will leverage your expertise in application security, utilizing tools such as SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), and SCA (Software Composition Analysis) to perform both static and dynamic source code reviews. Additionally, you will employ threat modeling and threat actor attack pathing to continually validate the effectiveness of the customer’s security controls.
The primary goal is to ensure that the security controls implemented by the organization are functioning as intended. By doing so, you will enhance the overall security defenses and collaborate with global development teams to maintain the ongoing security of the globally adopted application.
Job Description Highlights
Leadership and Mentorship:
- Lead and mentor a team of penetration testers, providing guidance and support to ensure high-quality security assessments.
- Conduct and oversee thorough security testing of developer operations and mobile applications (iPhone and Android).
- Identify security issues and vulnerabilities.
- Perform and supervise in-depth source code reviews to identify security flaws or weaknesses.
- Execute and oversee detailed assessments, compile findings into reports, and present actionable recommendations to stakeholders.
- Develop and implement security testing strategies and best practices to enhance the organization’s security posture.
- Collaborate with global development teams to maintain the ongoing security of the globally adopted application.
- Bachelor’s degree in computer science, Software Engineering, or related field, or equivalent job experience.
- Professional certifications such as GWAPT (GIAC Web Application Penetration Tester), OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), or similar.
- 5-7 years of experience in application security testing and source code review with at least 2 years in a leadership role.
- Proficiency in multiple programming languages and understanding of secure coding practices.
- Strong analytical skills and attention to detail for identifying vulnerabilities.
- Testing Developer Flows and Mobile Apps: Conducts thorough security testing of developer workflows and mobile applications (for both iPhone and Android platforms), identifying security issues and vulnerabilities.
- Conducting Source Code Reviews: Performs in-depth source code reviews to identify security flaws or weaknesses that could be exploited in software applications.
- Executing Tests/Assessments and Drafting Reports: Executes detailed assessments and compiles findings into reports for further review and action.
Experience with tools like Burp Suite Pro, Checkmarx, Corellium, Synopsys, Acunetix, VeraCode, SAST & DAST Tools, Plextrac, Cloud security (AWS / Azure / Oracle), Postman, SmartBear ReadyAPI, SoapUI, and Hashicorp Vault.
Benefits
Beyond a role, joining OnDefend means becoming part of a community dedicated to making a difference. Our client offers:
Health and Wellness
- Health Insurance: Comprehensive health insurance plans covering medical, dental, and vision.
- Health Insurance: Comprehensive health insurance plans covering medical, dental, and vision.
- 401(k) Matching: Company matches contributions to the 401(k) retirement plan up to a certain percentage.
- Generous Paid Time Off (PTO): Including vacation days, sick leave, and holidays to help you recharge and spend time with loved ones.
- Training and Development: Access to professional development programs, workshops, and certifications.
- Tuition Reimbursement: Financial support for further education and courses related to the job.
- Career Growth Opportunities: Clear career progression paths and opportunities for promotion.
- Inclusive Environment: A diverse and inclusive workplace where all employees feel valued.
- Team Building Activities: Regular team-building events and social gatherings.
- Technology and Tools: Access to the latest technology and tools needed to perform the job effectively.
-
Lead Application Penetration Tester
2 months ago
Washington, United States Kavaliro Full timeKavaliro is seeking an experienced Lead Application Penetration Tester to join our cyber security client. This role is perfect for someone passionate about cybersecurity and skilled in identifying and mitigating vulnerabilities in application security. As the lead, you'll be responsible for the security of cloud-native, microservices-based applications,...
-
Lead Application Penetration Tester
7 days ago
washington, United States Editech Staffing Full timeOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Lead Application Penetration Tester to join their dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful candidate will play a...
-
Lead Application Penetration Tester
2 weeks ago
washington, United States Editech Staffing Full timeOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Lead Application Penetration Tester to join their dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful candidate will play a...
-
Application Penetration Tester
3 weeks ago
Washington, United States Editech Staffing Full timeApplication Penetration TesterOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful...
-
Penetration Tester
1 month ago
washington, United States Editech Staffing Full timeJob OverviewOur client is looking for an experienced Application Penetration Tester to assess the security of a cloud-native, microservices-based architecture. You will focus on web and mobile applications, cloud security testing, adversary emulation, and continuous security improvement.Key responsibilities include static and dynamic source code reviews...
-
Penetration Tester
2 months ago
Washington, United States Editech Staffing Full timeJob OverviewOur client is looking for an experienced Application Penetration Tester to assess the security of a cloud-native, microservices-based architecture. You will focus on web and mobile applications, cloud security testing, adversary emulation, and continuous security improvement.Key responsibilities include static and dynamic source code reviews...
-
Application Penetration Tester
2 weeks ago
washington, United States Editech Staffing Full timeOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful candidate will play a...
-
Application Penetration Tester
2 weeks ago
washington, United States Editech Staffing Full timeOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful candidate will play a...
-
Application Penetration Tester
2 weeks ago
Washington, DC, United States Editech Staffing Full timeApplication Penetration TesterOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful...
-
Washington, Washington, D.C., United States Sev1Tech Full timeJob Title: Vulnerability Analyst and Penetration Tester LeadAbout the Role:Sev1Tech is seeking a highly skilled Vulnerability Analyst and Penetration Tester Lead to join our team. As a key member of our cybersecurity team, you will be responsible for conducting vulnerability assessments and penetration testing to identify potential security threats and...
-
Application Penetration Tester
3 weeks ago
Washington, United States Editech Staffing Full timeOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful candidate will play a...
-
Washington, Washington, D.C., United States Sev1Tech Full timeJob Title: Vulnerability Analyst and Penetration Tester LeadSev1Tech is seeking a highly skilled Vulnerability Analyst and Penetration Tester Lead to join our team. As a key member of our cybersecurity team, you will be responsible for conducting vulnerability assessments and penetration testing to identify potential security threats and vulnerabilities in...
-
Application Security Penetration Tester
4 weeks ago
Washington, Washington, D.C., United States Insight Global Full timeWe are seeking a skilled Application Security Penetration Tester to join our team at Insight Global in Washington, DC.This individual will work closely with a team of 5 to conduct source code reviews and penetration testing to identify security concerns and vulnerabilities within mobile applications.The successful candidate will have experience with source...
-
Penetration Tester
2 weeks ago
Washington, United States Insight Global Full timeJob DescriptionJob DescriptionMust Haves:4+ years of experience conducting manual Source Code reviewsExperience with automated testing tools for SAST (Static Application security Testing), DAST (dynamic Application security Testing), and SCA (software Composition Analysis)Example tools: Checkmarx, Burp Suite Pro, Plextrac, Veracode, Hashicorp Vault4+ years...
-
Cybersecurity Penetration Tester Associate
4 weeks ago
Washington, Washington, D.C., United States Ankura Full timeCybersecurity Penetration Tester Job DescriptionAnkura is a team of excellence founded on innovation and growth. Our Cybersecurity Practice offers a full-service suite of information security and privacy solutions for clients, regardless of industry or size.We provide proactive preparedness, incident response, cyber resilience, and managed advisory services...
-
Application Penetration Tester
2 weeks ago
Washington, DC, United States Editech Staffing Full timeOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The successful candidate will play a...
-
Lead Application PenetrationTester
3 weeks ago
Washington, United States Editech Staffing Full timeLead Application Penetration TesterOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Lead Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The...
-
Lead Application PenetrationTester
2 weeks ago
washington, United States Editech Staffing Full timeLead Application Penetration TesterOnsite / Washington, DCJob OverviewOur client is seeking a highly skilled and experienced Lead Application Penetration Tester to join our dynamic team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities. The...
-
Lead Application Security Specialist
4 weeks ago
Washington, Washington, D.C., United States Editech Staffing Full timeJob DescriptionEditech Staffing is seeking a highly skilled and experienced Lead Application Security Specialist to join our team. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities.The successful candidate will play a critical role in...
-
Lead Application Security Specialist
4 weeks ago
Washington, Washington, D.C., United States Editech Staffing Full timeJob OverviewWe are seeking a highly skilled and experienced Lead Application Penetration Tester to join our dynamic team at Editech Staffing. This role is ideal for someone with a passion for cybersecurity, a deep understanding of application security, and the ability to identify and mitigate vulnerabilities.The successful candidate will play a critical role...