Penetration Testing Engineer
6 days ago
Job Summary –
Cybersecurity Penetration Testing Engineer – Application & API Security
Location – preferably in Charlotte, NC
Must have - Expertise in Burp Suite, API testing and Penetration Testing
Job Summary –
The Penetration Testing Engineer
will be responsible for conducting in-depth
web application, mobile application, and API security testing
across business-critical platforms.
The role requires
hands-on expertise in Burp Suite
, deep understanding of
offensive security methodologies
, and the ability to identify, exploit, and document security vulnerabilities.
The engineer will work closely with development, DevSecOps, and risk teams to
ensure secure SDLC practices
and support remediation of discovered vulnerabilities.
Years of experience needed –
5–8 years of total experience in application or API penetration testing, with at least 3+ years in hands-on offensive test
Key Responsibilities:
1. Penetration Testing & Vulnerability Assessment
- Perform
manual and automated penetration testing
on web, mobile, and API endpoints. - Use
Burp Suite Professional
extensively for intercepting, modifying, and exploiting HTTP/S traffic. - Conduct
source code-assisted testing
when applicable to identify deeper logic flaws. - Simulate real-world attack scenarios using
OWASP Top 10, SANS 25, and API Security Top 10
frameworks. - Identify authentication, authorization, session management, and input validation flaws.
2. API Security Testing
- Perform
REST and GraphQL API penetration testing
, including JWT, OAuth, and token manipulation. - Validate
business logic vulnerabilities
and parameter tampering across microservices. - Use tools such as
Postman, Burp Suite, and OWASP ZAP
for fuzzing, interception, and payload injection. - Validate API schema misconfigurations, rate limiting, and data exposure issues.
3. Offensive Security & Exploitation
- Execute
custom payloads and exploits
to demonstrate risk severity to stakeholders. - Develop
proof-of-concept (PoC)
exploits to validate identified vulnerabilities. - Emulate attacker tactics, techniques, and procedures (TTPs) from
MITRE ATT&CK
and
CWE
references. - Perform targeted assessments on authentication bypass, privilege escalation, and input deserialization.
4. Reporting & Remediation Support
- Document detailed findings, reproduction steps, impact analysis, and mitigation recommendations.
- Collaborate with developers and DevSecOps teams to ensure timely patching and secure code fixes.
- Participate in
vulnerability triage
and
retesting
post-remediation. - Present reports to technical and management stakeholders in clear, risk-prioritized language.
5. Security Process & Continuous Improvement
- Integrate testing results into
CI/CD pipelines
where possible (DevSecOps enablement). - Contribute to
secure coding guidelines
and training sessions for developers. - Evaluate emerging attack trends, new CVEs, and offensive security tools to keep the testing framework current.
- Assist in developing internal scripts, extensions, or automation workflows for testing efficiency.
Technical Skills
Core Tools & Techniques
- Burp Suite Professional
– expert-level usage (Intruder, Repeater, Decoder, Extender). - Familiarity with
OWASP ZAP
,
Nmap
,
Metasploit
,
SQLmap
,
DirBuster
,
Hydra
, and
Ffuf
. - Deep understanding of
OWASP Top 10
(Web & API) and
CWE Top 25
vulnerabilities. - Strong ability to identify and exploit
logic-based and authentication-related flaws
.
Programming & Scripting
- Proficiency in at least one scripting language:
Python, JavaScript, or Bash
. - Experience writing small custom scripts or Burp extensions for advanced payloads.
- Understanding
HTTP/HTTPS
,
REST
,
GraphQL
,
JSON
, and
XML
protocols.
Offensive Security
- Practical experience in
vulnerability exploitation
,
reverse engineering
, or
red team
engagements. - Familiarity with
exploit development frameworks
,
C2 tools (Cobalt Strike, Empire)
is a plus. - Ability to simulate APT-style threat actor behavior and persistence mechanisms.
API / Cloud Security (Preferred)
- Knowledge of
API gateways (Kong, Apigee)
and
microservices architectures
. - Awareness of
cloud-native security testing (AWS, Azure, GCP)
and container security (Docker/Kubernetes).
Qualifications
- Bachelor's or Master's degree in Computer Science, Information Security, or related field.
- 5–8 years of total experience in
application or API penetration testing
, with at least 3+ years in
hands-on offensive testing
. - Strong report writing and presentation skills for both technical and non-technical audiences.
- Preferred Certifications:
·
OSCP / OSWE / OSEP
(Offensive Security)
·
Burp Suite Certified Practitioner (BSCP)
· eWPTX / eCPPT / CEH (Practical)
· GWAPT / GPEN / GCPN
-
Performance Test Engineer with IVR
6 days ago
Charlotte, North Carolina, United States Centraprise Full time $120,000 - $180,000 per yearJob Role: Performance Test Engineer with IVR ExpLocation: Charlotte, NC ONSITEJob Type: FulltimeJob Description:Must Have Technical/Functional SkillsRequired Skills:Expert in Cyara testing suite and other industry standard telephony testing toolsLoad Runner (VuGen) scripting experience at medium to high level of expertiseUnderstanding of basic performance...
-
Sr. Automation Test Engineer
4 days ago
Charlotte, North Carolina, United States UST Full time $78,000 - $117,000 per year1 OpeningCharlotteRole descriptionSr. Automation Test EngineerLead II - Software TestingWho We Are:Born digital, UST transforms lives through the power of technology. We walk alongside our clients and partners, embedding innovation and agility into everything they do. We help them create transformative experiences and human-centered solutions for a better...
-
ETL Test Engineer
5 days ago
Charlotte, North Carolina, United States Wipro Full time $60,000 - $135,000 per yearJob description:Job DescriptionRole PurposeThe purpose of the role is to support process delivery by ensuring daily performance of the Production Specialists, resolve technical escalations and develop technical capability within the Production Specialists. ͏Required Skills:10+ years of experience in ETL, TOSCA, Mobile Testing, and Software Quality...
-
ETL Testing
6 days ago
Charlotte, North Carolina, United States Synechron Full time $90,000 - $95,000 per yearWe areAt Synechron, we believe in the power of digital to transform businesses for the better. Our global consulting firm combines creativity and innovative technology to deliver industry-leading digital solutions. Synechron's progressive technologies and optimization strategies span end-to-end Artificial Intelligence, Consulting, Digital, Cloud & DevOps,...
-
Subsurface Utility Engineering
6 days ago
Charlotte, North Carolina, United States Gannett Fleming, Inc. Full time $30 - $35GFT is seeking a Subsurface Utility Engineering (SUE) Technician II to join our Construction Services Team in Charlotte, NC This role follows an in-office work model, requiring regular attendance at field locations or in the Charlotte, NC office.At GFT, we're not just engineering the future; we're meticulously building it. Our comprehensive suite of...
-
Test Automation Engineer
6 days ago
Charlotte, North Carolina, United States CapB InfoteK Full time $60,000 - $120,000 per yearFor one pf our long-term multiyear projects, we are looking for a Test Automation Engineer out of Charlotte, NC.Skills & Responsibilities:1) 5+ years' experience in Java, Selenium, Cucumber BDD, Maven, Gradle, GIT, TestNG,2) Ability to design Enterprise Level Automation Framework (Keyword-Driven, Data-Driven, Page Object, Hybrid) for Cross Browser Web,...
-
Ultrasonic Testing Technician
6 days ago
Charlotte, North Carolina, United States S&ME, Inc. Full time $60,000 - $90,000 per yearUltrasonic Testing Technician Requisition Number: Build Your Career. Own Your Future.At S&ME, you're more than just an employee, you're an employee-owner of a 100% employee-owned company that has been solving complex geotechnical, civil, environmental, and construction materials testing challenges for over 50 years. We're invested in your success and offer a...
-
Charlotte, North Carolina, United States WSP Full time $40,000 - $50,000 per yearDescriptionThis Opportunity WSP USA hosts hundreds of internships across the United States to gain hands-on, meaningful work experience to enhance their education and professional aptitude. Our interns gain exposure to real projects while working side by side with senior staff. Through our Developing Professionals Network, interns gain mentorship,...
-
Specialty Technician
4 days ago
Charlotte, North Carolina, United States ECS Limited Full time $65,000 - $85,000 per yearWhat You'll Do:ECS Limited is offering a unique opportunity for a talented Specialty Technician to join our Charlotte team and advance in a dynamic work environment. You'll work on a variety of projects of moderate complexity performing field observations and inspections, and may also work with steel performing destructive and non-destructive testing...
-
Special Inspector
4 days ago
Charlotte, North Carolina, United States ECS Ltd Full time $70,000 - $85,000 per yearResponsibilitiesECS Limited is offering a unique opportunity for an experienced Special Inspector / Specialty Technician III to join our Charlotte team and advance in a dynamic work environment. You'll work on a variety of complex projects performing field observations and inspections, and may also work with steel performing destructive and non-destructive...