Cloud-Based Web APIs Penetration Testing Support Consultant

3 weeks ago


San Francisco, California, United States Hybrid Pathways Full time

About the opportunity:
New Era Technology is seeking a a Penetration Testing Support Consulting Resident to conduct testing for web APIs for indirect object access permissions and controls on AWS. This is a 5-month remote opportunity.

Write RSpec tests in Ruby to ensure code quality.
Set up API endpoint calls using Postman or a similar tool for testing purposes.
Create Python scripts for reporting and for triaging issues.
Establish a test environment to confirm test case validity.
Research API endpoint functionality to clarify desired behaviors.
Verify that each API endpoint functions as intended and meets the specified requirements.
Identify the owner of each endpoint by reviewing code and documentation.
Troubleshoot any issues that arise to maintain smooth testing operations.
Analyze test results and diligently report any defects discovered.
Continuously enhance test automation by updating and maintaining the test framework.
Communicate progress and address any issues through regular status reports.
Collaborate with API developers to tailor testing and analysis.
Conduct penetration testing for web APIs for indirect object access permissions and controls on AWS.
Document and report detailed penetration testing results, findings and gaps.
Support analysis, recommendations and potential remediation of identified vulnerabilities.
Collaborate with related Information Security Trust Assurance and Threat Detection teams to characterize potential security vulnerabilities.
Validate and/or enhance testing protocols, tools or scripts to optimize penetration testing processes.
Independently handle complex issues with minimal supervision, while escalating only the most complex issues to appropriate staff.
Provide guidance and recommendations to stakeholders responsible for security remediation actions to close identified gaps and remediation validation testing.
Develop comprehensive and accurate reports and presentations for various consumers of penetration testing results.
Developing, extending, or modifying exploits, shellcode, or exploit tools.


5+ years experience conducting penetration testing.
3+ years experience conducting vulnerability analysis.
Test Automation and Frameworks: Proficiency in writing automated tests using RSpec, a testing tool for Ruby. Understanding of test automation frameworks and principles is crucial.
Programming Knowledge: Strong knowledge of Ruby programming language to write tests. Working knowledge of Python and possibly some familiarity with other languages used in the codebase.
API Testing: Experience with API testing tools such as Postman or similar software to create and send requests to API endpoints and analyze responses.
Environment Setup: Ability to set up and maintain test environments, including configuration of databases, servers, and other services that tests depend on.
Troubleshooting: Skills in identifying, diagnosing, and resolving issues that arise during testing. This often requires a good understanding of the system being tested and problem-solving skills.
Version Control Systems: Familiarity with version control systems like Git for searching through code and documentation to identify endpoint owners.
Defect Tracking: Experience with defect tracking and reporting tools to log and manage issues discovered during testing.
Continuous Integration/Continuous Deployment (CI/CD): Understanding of CI/CD principles to integrate automated tests with build pipelines.
Hands on experience with the following:

Scripting Languages (e.g., Python, PowerShell, etc.)
Linux Operating Systems
AWS Security Services
AWS Infrastructure Services
Network protocols (e.g., TCP/IP, UDP, ARP, DNS, and DHCP)
Ability to identify and exploit web vulnerabilities (XSS, CSRF, SQLi, SSRF, arbitrary file upload, etc.)
Ability to identify and exploit mobile vulnerabilities (API issues, insecure storage, memory corruption, deep links, etc.)
Cryptography (e.g., PKI, TLS, etc.)
Web Application penetration testing
Working knowledge of Identity and Access Management and Authentication Protocols including Active Directory and Entra ID

Familiarity with the following:

Windows Operating Systems
Source code vulnerability analysis


Taking initiative and being proactive
Excellent interpersonal communication skills with strong spoken and written English.
Collaborative team worker – both in person and virtually using MS Teams or similar.
Excellent analytical skills.


  • San Francisco, California, United States Early Warning Services LLC Full time

    About the RoleWe are seeking a highly skilled and experienced Lead Cybersecurity Engineer to join our team at Early Warning Services LLC. As a key member of our security team, you will be responsible for identifying and documenting security vulnerabilities through approved penetration testing activities to secure our systems, infrastructure, and...


  • San Diego, California, United States RSI Security Full time

    THIS IS A REMOTE POSITIONRSI Security is a small organization where collaboration is not only encouraged, but expected. We value relationships within our team and are intentional to build and maintain a strong team camaraderie through virtual happy hours, daily morning meetings to help us start off on the right foot, and meetings dedicated solely to...


  • San Jose, California, United States Tech Mahindra Full time

    Job DescriptionKey Responsibilities:• Web Technologies Support: Provide technical assistance and troubleshooting for web-based applications, ensuring seamless compatibility and performance across different browsers, especially Chrome.• Cloud Services Management: Monitor and maintain applications hosted on cloud platforms, including Google Cloud Platform...


  • San Francisco, California, United States BHO Tech Full time

    **About BHO Tech**We are a small, agile team working on a cloud-based ensemble of optimization tools that integrates seamlessly into existing infrastructure. Our clients include globally recognized leaders in the insurance, credit card, algorithmic trading, and consumer packaged goods industries.We're looking for versatile developers who feel comfortable...


  • San Francisco, California, United States Amazon Web Services, Inc. Full time

    Job Overview:We are looking for a Cloud Solutions Architect at Amazon Web Services, Inc. In this pivotal role within the Solutions Architect team, you will serve as a trusted consultant to managed systems integrators, offering architectural insights and strategies to enhance and expedite partner collaborations globally.Core Responsibilities:Serve as a...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Visa candidates are welcome to apply.In the evolving landscape of retail, where shopping dynamics have transformed significantly, it is essential for technology to play a pivotal role in driving our company forward. The Web Application Security Engineer is a vital member of the Information Security team, ensuring that our technological frameworks are robust...

  • Web Developer

    3 months ago


    San Francisco, California, United States ITJobsList Full time

    Our client is actually looking for a senior-level software engineer that could design and create extremely scalable tolerant net APIs as well as distributed services. Essential Job Functions Participate in Agile preparation as well as execution Develop API characteristics bug fixes as well as automation tools. Strong master software growth encounters Strong...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Visa candidates are encouraged to apply.The landscape of retail has transformed significantly in recent years, necessitating a stronger focus on technology and personnel investment. To keep pace with these rapid changes, it is essential for technology to serve as a key facilitator for our organization, enabling swift delivery, adaptability to market...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Visa candidates are encouraged to apply.The landscape of retail has transformed significantly in recent years, necessitating a stronger emphasis on both personnel and technological advancements. As we navigate these rapid shifts, it is essential for technology to serve as a key facilitator, enabling our organization to swiftly adapt to market dynamics and...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Visa candidates are welcome to apply.In the evolving landscape of retail, where technology plays a pivotal role, it is essential for our organization to leverage innovative solutions that enhance operational efficiency and respond swiftly to market dynamics. The role of the Web Application Security Engineer is integral to our Information Security team,...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Visa candidates are welcome to apply.In the rapidly evolving landscape of retail, it is essential to leverage technology as a key driver for our organization. The role of the Web Application Security Engineer is integral to our Information Security team, ensuring that we remain adaptive to market shifts and responsive to customer needs.Key...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Visa candidates are encouraged to apply.The landscape of retail has transformed significantly in recent years, necessitating a greater emphasis on both personnel and technological advancements. As we navigate these rapid shifts, it is essential for technology to serve as a strategic facilitator, enabling our organization to enhance delivery, adapt to market...


  • San Francisco, California, United States Forhyre Full time

    Job OverviewWe are seeking a seasoned Informatica Consultant with expertise in Google Cloud Platform (GCP) to join our team at Forhyre. As a key member of our technical team, you will be responsible for leading technical solution discovery with large enterprise-level merchants, creating innovative solution proposals and designs, and collaborating with...


  • San Francisco, California, United States Amazon Web Services, Inc. - A97 Full time

    About the RoleWe are seeking a highly skilled Cloud Solutions Architect to join our team at Amazon Web Services, Inc. - A97. As a Cloud Solutions Architect, you will play a key role in helping our customers achieve their full potential by providing expert guidance on cloud-based solutions.Key ResponsibilitiesInteract with CxO/VP level executives, developers,...


  • San Francisco, California, United States Amazon Web Services, Inc. Full time

    About the Role:Amazon Web Services (AWS) is seeking a dedicated Cloud Solutions Architect to drive the adoption of cloud technologies within the Financial Services Industry (FSI). This position offers a unique opportunity to engage with a diverse range of clients, from small enterprises to large public sector organizations.Your Responsibilities:As a Cloud...


  • San Francisco, California, United States Amazon Web Services, Inc. Full time

    Overview: Amazon Web Services (AWS) is at the forefront of cloud computing, driving revenue and growth for a diverse range of clients, from small businesses to large enterprises, including public sector organizations.Role Summary: As a Cloud Partner Solutions Architect, you will play a pivotal role in assisting renowned systems integrators and technology...


  • San Francisco, California, United States Amazon Web Services, Inc. Full time

    About the RoleAWS Sales, Marketing, and Global Services (SMGS) plays a pivotal role in driving revenue, adoption, and growth across a diverse range of customers, from small and mid-market accounts to large enterprises, including public sector entities. Your MissionAre you eager to assist renowned systems integrators (SIs) and technology partners in...


  • San Francisco, California, United States Amazon Web Services, Inc. - A97 Full time

    About the RoleWe are seeking a highly skilled Cloud Storage Specialist to join our team at Amazon Web Services, Inc. - A97. As a Cloud Storage Specialist, you will be responsible for helping startups scale quickly and cost-effectively on AWS.Key ResponsibilitiesInteract with CxO/VP level executives, developers, and technical architects to ease adoption,...

  • Web Developer

    1 month ago


    San Francisco, California, United States EXPERIS Full time

    Sr.Web Developer (.Net) Hybrid form San Francisco, CA or Austin TX $75 - $78/hr on W2 Job Description This individual should have a passion for keeping up-to-date and using cutting-edge web technologies to build interactive technologies.Successful candidates have the ability to be self-directed and interact with technology and business partners web...

  • Web Developer

    2 months ago


    San Francisco, California, United States Experis Full time

    Sr. Web Developer (.Net)Hybrid form San Francisco, CA or Austin TX$75 - $78/hr on W2Job DescriptionThis individual should have a passion for keeping up-to-date and using cutting-edge web technologies to build interactive technologies. Successful candidates have the ability to be self-directed and interact with technology and business partners web...