Web Application Security Tester
3 weeks ago
Web Application Security Tester Job Locations US-GA-Smryna Job ID 2025-2014 Category CyberSecurity Type Regular Full-Time Clearance Required Secret Overview Title: Web Application Security Tester Location: Herndon, VA- Remote in States Foxhole is registered to do business Clearance: Active DoD Secret Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs. Our talented employee-owners provide agile, scalable services and solutions that solve operational gaps, operate critical systems, and protect and secure the enterprise - across the organization and around the world. Support the Web Application Security Program (WASP) mission to ensure that security is integrated systematically and comprehensively throughout the Software Development Life Cycle (SDLC). Job Description Perform security reviews of web application architectures, APIs, and supporting infrastructure. Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using industry-standard tools. Conduct application spidering, fuzzing, and business logic abuse testing to identify vulnerabilities. Execute Web Application Penetration Testing against modern frameworks (e.g., React, Angular, Node.js, Django, Flask, .NET Core). Test APIs using REST and GraphQL fuzzing, schema validation, and security automation. Identify and validate vulnerabilities such as: OWASP Top 10 Business Logic flaws API Security vulnerabilities (OWASP API Top 10) Authentication and authorization weaknesses Deserialization and injection flaws Conduct manual exploit validation beyond automated tool output to reduce false positives. Develop and maintain test automation scripts using frameworks like Burp Suite Extender API, ZAP scripting, and custom Python tools. Integrate security testing into CI/CD pipelines using GitLab CI, GitHub Actions, Jenkins, or Azure DevOps. Utilize SCA (Software Composition Analysis) tools to identify vulnerable dependencies (e.g., Snyk, Dependency-Check, Black Duck). Implement the Common Weakness Scoring System (CWSS) and assist in Common Vulnerability Scoring System (CVSS) ratings for prioritization. Generate technical reports and provide remediation guidance to developers, system owners, and ISSOs. Provide monthly and annual program metrics including trends in vulnerability classes, remediation timelines, and residual risk. Minimum Requirements Active DoD Secret security clearance 5 + years of progressive incident response experience DoD IAT II required certification/s (one of the following): CCNA-Security, CySA+ (CSA+), GICSP, GSEC, Security+ CE, CND, SSCP, GWAPT, OSWE, eWPT CSSP-AUrequired certification/s (one of the following): GSNA, CISA Required Tools & Hands-On Skills Web Security Testing & Automation: Burp Suite Pro, OWASP ZAP, Postman, Fiddler, mitmproxy. SAST/DAST: Checkmarx, Fortify, Veracode, SonarQube, Acunetix, AppScan. SCA (Software Composition Analysis): Snyk, OWASP Dependency-Check, Black Duck, Mend. Fuzzing & Exploit Development: AFL, Peach Fuzzer, boofuzz. API Security Testing: Postman, Insomnia, ReadyAPI, Burp Suite extensions for GraphQL/REST. CI/CD Security Integration: GitLab CI, Jenkins, GitHub Actions, Azure DevOps with security plugins. Containers & Cloud Security (preferred): Docker, Kubernetes, AWS Inspector, Prisma Cloud. Desired Experience/Certifications Strong knowledge of the OWASP Top 10 and OWASP ASVS. Familiarity with CWE, NIST 800-53/171, and DISA STIGs. Hands-on experience with scripting languages (Python, Bash, PowerShell, JavaScript). Familiarity with DevSecOps practices and secure coding guidelines. Ability to communicate complex findings clearly to both technical and non-technical stakeholders. More Information Requirements of position: Think analytically, effective verbal and written communication skills, make decisions, observe/remember details, interpret data, concentrate on tasks, adjust to change, handle stress/emotions. Regular attendance, maintain work schedule, attend meetings, meet deadlines, keyboard/type, handle confidential information, use math/calculations, stay organized, operate office equipment, may direct others. May be exposed to dust/dirt, humidity, and noise. Foxhole Technology is an Equal Opportunity Employer and makes hiring decisions without regard to race, color, religion, sex (including pregnancy, childbirth and sexual orientation), national origin, age, disability, genetic information, military/veteran status, or any other protected class. Need help finding the right job? We can recommend jobs specifically for you Click here to get started.
-
Web Application Security Tester
4 days ago
Smyrna, GA, United States Foxhole Technology Full timeWeb Application Security TesterJob Locations US-GA-SmrynaJob ID 2025-2014Category CyberSecurityType Regular Full-TimeClearance Required SecretOverviewTitle: Web Application Security Tester Location: Herndon, VA- Remote in States Foxhole is registered to do business Clearance: Active DoD Secret Foxhole Technology provides robust cybersecurity and IT...
-
Web Application Security Tester
1 week ago
Smyrna, GA, United States Foxhole Technology Full timeWeb Application Security TesterJob Locations US-GA-SmrynaJob ID 2025-2014Category CyberSecurityType Regular Full-TimeClearance Required SecretOverviewTitle: Web Application Security Tester Location: Herndon, VA- Remote in States Foxhole is registered to do business Clearance: Active DoD Secret Foxhole Technology provides robust cybersecurity and IT...
-
Web Application Security Tester
4 weeks ago
Smyrna, United States Foxhole Technology Full timeWeb Application Security Tester Job Locations US-GA-Smryna Job ID 2025-2014 Category CyberSecurity Type Regular Full-Time Clearance Required Secret Overview Title: Web Application Security TesterLocation: Herndon, VA- Remote in States Foxhole is registered to do businessClearance: Active DoD Secret Foxhole Technology provides robust cybersecurity and IT...
-
Web Application Security Tester
2 weeks ago
Smyrna, Georgia, United States Foxhole Technology, Inc. Full time $120,000 - $140,000 per yearOverviewTitle: Web Application Security TesterLocation: Herndon, VA- Remote in States Foxhole is registered to do businessClearance: Active DoD Secret Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers...
-
Lead Application Security Engineer
3 days ago
Smyrna, GA, United States Cox Automotive Full timeThe Lead Application Security Engineer will partner with Security Engineering Enablement and Security Architecture to design and ship secure software: secure code reviews and help define requirements on prerelease control validation (SAST/DAST/SCA, API security, Container/IaC scans). Drive fix-first coaching-turn findings into clear remediation guidance and...
-
SOC Manager with Security Clearance
5 days ago
Smyrna, United States Crest Security Assurance Full timeManages a team of cybersecurity professionals within a 24x7x365 Security Operations Center (SOC), with a primary shift schedule of 8:00 AM to 5:00 PM on-site. This role requires comprehensive oversight of day-to-day SOC activities to protect the agency’s digital infrastructure from evolving cyber threats. The position is responsible for managing personnel,...
-
SOC Manager with Security Clearance
4 days ago
Smyrna, United States Crest Security Assurance Full timeManages a team of cybersecurity professionals within a 24x7x365 Security Operations Center (SOC), with a primary shift schedule of 8:00 AM to 5:00 PM on-site. This role requires comprehensive oversight of day-to-day SOC activities to protect the agencys digital infrastructure from evolving cyber threats. The position is responsible for managing personnel,...
-
SOC Manager with Security Clearance
2 weeks ago
Smyrna, United States Crest Security Assurance Full timeManages a team of cybersecurity professionals within a 24x7x365 Security Operations Center (SOC), with a primary shift schedule of 8:00 AM to 5:00 PM on-site. This role requires comprehensive oversight of day-to-day SOC activities to protect the agencys digital infrastructure from evolving cyber threats. The position is responsible for managing personnel,...
-
SOC Technical Lead with Security Clearance
2 weeks ago
Smyrna, United States Crest Security Assurance Full timeServe as the technical lead within a 24x7x365 Security Operations Center (SOC), supporting the leadership of a team of cybersecurity professionals during the primary shift of 8:00 AM to 5:00 PM on-site. This role is responsible for guiding the technical direction of SOC operations, including hands-on involvement in incident detection, analysis, containment,...
-
IT Application Support Analyst
2 weeks ago
Smyrna, United States Synergis Full timeIT Application Support AnalystDirect-HireHybrid| Atlanta, GASynergis’ client, one the leading business product wholesales in the United States, has engaged Synergis in a search for an IT Application Support Analyst. You will be responsible for the resolution of second level service incidents for internally developed applications, application enhancements,...