Penetration Testing Engineer

6 days ago


Charlotte, North Carolina, United States Tanisha Systems, Inc Full time $80,000 - $120,000 per year

Job Summary –

Cybersecurity Penetration Testing Engineer – Application & API Security

Location – preferably in Charlotte, NC

Must have - Expertise in Burp Suite, API testing and Penetration Testing

Job Summary –

The Penetration Testing Engineer
will be responsible for conducting in-depth
web application, mobile application, and API security testing
across business-critical platforms.

The role requires
hands-on expertise in Burp Suite
, deep understanding of
offensive security methodologies
, and the ability to identify, exploit, and document security vulnerabilities.

The engineer will work closely with development, DevSecOps, and risk teams to
ensure secure SDLC practices
and support remediation of discovered vulnerabilities.

Years of experience needed –
5–8 years of total experience in application or API penetration testing, with at least 3+ years in hands-on offensive test

Key Responsibilities:

1. Penetration Testing & Vulnerability Assessment

  • Perform
    manual and automated penetration testing
    on web, mobile, and API endpoints.
  • Use
    Burp Suite Professional
    extensively for intercepting, modifying, and exploiting HTTP/S traffic.
  • Conduct
    source code-assisted testing
    when applicable to identify deeper logic flaws.
  • Simulate real-world attack scenarios using
    OWASP Top 10, SANS 25, and API Security Top 10
    frameworks.
  • Identify authentication, authorization, session management, and input validation flaws.

2. API Security Testing

  • Perform
    REST and GraphQL API penetration testing
    , including JWT, OAuth, and token manipulation.
  • Validate
    business logic vulnerabilities
    and parameter tampering across microservices.
  • Use tools such as
    Postman, Burp Suite, and OWASP ZAP
    for fuzzing, interception, and payload injection.
  • Validate API schema misconfigurations, rate limiting, and data exposure issues.

3. Offensive Security & Exploitation

  • Execute
    custom payloads and exploits
    to demonstrate risk severity to stakeholders.
  • Develop
    proof-of-concept (PoC)
    exploits to validate identified vulnerabilities.
  • Emulate attacker tactics, techniques, and procedures (TTPs) from
    MITRE ATT&CK
    and
    CWE
    references.
  • Perform targeted assessments on authentication bypass, privilege escalation, and input deserialization.

4. Reporting & Remediation Support

  • Document detailed findings, reproduction steps, impact analysis, and mitigation recommendations.
  • Collaborate with developers and DevSecOps teams to ensure timely patching and secure code fixes.
  • Participate in
    vulnerability triage
    and
    retesting
    post-remediation.
  • Present reports to technical and management stakeholders in clear, risk-prioritized language.

5. Security Process & Continuous Improvement

  • Integrate testing results into
    CI/CD pipelines
    where possible (DevSecOps enablement).
  • Contribute to
    secure coding guidelines
    and training sessions for developers.
  • Evaluate emerging attack trends, new CVEs, and offensive security tools to keep the testing framework current.
  • Assist in developing internal scripts, extensions, or automation workflows for testing efficiency.

Technical Skills

Core Tools & Techniques

  • Burp Suite Professional
    – expert-level usage (Intruder, Repeater, Decoder, Extender).
  • Familiarity with
    OWASP ZAP
    ,
    Nmap
    ,
    Metasploit
    ,
    SQLmap
    ,
    DirBuster
    ,
    Hydra
    , and
    Ffuf
    .
  • Deep understanding of
    OWASP Top 10
    (Web & API) and
    CWE Top 25
    vulnerabilities.
  • Strong ability to identify and exploit
    logic-based and authentication-related flaws
    .

Programming & Scripting

  • Proficiency in at least one scripting language:
    Python, JavaScript, or Bash
    .
  • Experience writing small custom scripts or Burp extensions for advanced payloads.
  • Understanding
    HTTP/HTTPS
    ,
    REST
    ,
    GraphQL
    ,
    JSON
    , and
    XML
    protocols.

Offensive Security

  • Practical experience in
    vulnerability exploitation
    ,
    reverse engineering
    , or
    red team
    engagements.
  • Familiarity with
    exploit development frameworks
    ,
    C2 tools (Cobalt Strike, Empire)
    is a plus.
  • Ability to simulate APT-style threat actor behavior and persistence mechanisms.

API / Cloud Security (Preferred)

  • Knowledge of
    API gateways (Kong, Apigee)
    and
    microservices architectures
    .
  • Awareness of
    cloud-native security testing (AWS, Azure, GCP)
    and container security (Docker/Kubernetes).

Qualifications

  • Bachelor's or Master's degree in Computer Science, Information Security, or related field.
  • 5–8 years of total experience in
    application or API penetration testing
    , with at least 3+ years in
    hands-on offensive testing
    .
  • Strong report writing and presentation skills for both technical and non-technical audiences.
  • Preferred Certifications:

·
OSCP / OSWE / OSEP
(Offensive Security)

·
Burp Suite Certified Practitioner (BSCP)

· eWPTX / eCPPT / CEH (Practical)

· GWAPT / GPEN / GCPN



  • Charlotte, North Carolina, United States Centraprise Full time $120,000 - $180,000 per year

    Job Role: Performance Test Engineer with IVR ExpLocation: Charlotte, NC ONSITEJob Type: FulltimeJob Description:Must Have Technical/Functional SkillsRequired Skills:Expert in Cyara testing suite and other industry standard telephony testing toolsLoad Runner (VuGen) scripting experience at medium to high level of expertiseUnderstanding of basic performance...


  • Charlotte, North Carolina, United States UST Full time $78,000 - $117,000 per year

    1 OpeningCharlotteRole descriptionSr. Automation Test EngineerLead II - Software TestingWho We Are:Born digital, UST transforms lives through the power of technology. We walk alongside our clients and partners, embedding innovation and agility into everything they do. We help them create transformative experiences and human-centered solutions for a better...

  • ETL Test Engineer

    5 days ago


    Charlotte, North Carolina, United States Wipro Full time $60,000 - $135,000 per year

    Job description:Job DescriptionRole PurposeThe purpose of the role is to support process delivery by ensuring daily performance of the Production Specialists, resolve technical escalations and develop technical capability within the Production Specialists.  ͏Required Skills:10+ years of experience in ETL, TOSCA, Mobile Testing, and Software Quality...

  • ETL Testing

    6 days ago


    Charlotte, North Carolina, United States Synechron Full time $90,000 - $95,000 per year

    We areAt Synechron, we believe in the power of digital to transform businesses for the better. Our global consulting firm combines creativity and innovative technology to deliver industry-leading digital solutions. Synechron's progressive technologies and optimization strategies span end-to-end Artificial Intelligence, Consulting, Digital, Cloud & DevOps,...


  • Charlotte, North Carolina, United States Gannett Fleming, Inc. Full time $30 - $35

    GFT is seeking a Subsurface Utility Engineering (SUE) Technician II to join our Construction Services Team in Charlotte, NC This role follows an in-office work model, requiring regular attendance at field locations or in the Charlotte, NC office.At GFT, we're not just engineering the future; we're meticulously building it. Our comprehensive suite of...


  • Charlotte, North Carolina, United States CapB InfoteK Full time $60,000 - $120,000 per year

    For one pf our long-term multiyear projects, we are looking for a Test Automation Engineer out of Charlotte, NC.Skills & Responsibilities:1) 5+ years' experience in Java, Selenium, Cucumber BDD, Maven, Gradle, GIT, TestNG,2) Ability to design Enterprise Level Automation Framework (Keyword-Driven, Data-Driven, Page Object, Hybrid) for Cross Browser Web,...


  • Charlotte, North Carolina, United States S&ME, Inc. Full time $60,000 - $90,000 per year

    Ultrasonic Testing Technician Requisition Number: Build Your Career. Own Your Future.At S&ME, you're more than just an employee, you're an employee-owner of a 100% employee-owned company that has been solving complex geotechnical, civil, environmental, and construction materials testing challenges for over 50 years. We're invested in your success and offer a...


  • Charlotte, North Carolina, United States WSP Full time $40,000 - $50,000 per year

    DescriptionThis Opportunity WSP USA hosts hundreds of internships across the United States to gain hands-on, meaningful work experience to enhance their education and professional aptitude. Our interns gain exposure to real projects while working side by side with senior staff. Through our Developing Professionals Network, interns gain mentorship,...


  • Charlotte, North Carolina, United States ECS Limited Full time $65,000 - $85,000 per year

    What You'll Do:ECS Limited is offering a unique opportunity for a talented Specialty Technician to join our Charlotte team and advance in a dynamic work environment. You'll work on a variety of projects of moderate complexity performing field observations and inspections, and may also work with steel performing destructive and non-destructive testing...

  • Special Inspector

    4 days ago


    Charlotte, North Carolina, United States ECS Ltd Full time $70,000 - $85,000 per year

    ResponsibilitiesECS Limited is offering a unique opportunity for an experienced Special Inspector / Specialty Technician III to join our Charlotte team and advance in a dynamic work environment. You'll work on a variety of complex projects performing field observations and inspections, and may also work with steel performing destructive and non-destructive...