Web Application Security Tester

2 weeks ago


Smyrna, Georgia, United States Foxhole Technology, Inc. Full time $120,000 - $140,000 per year
Overview

Title: Web Application Security Tester

Location: Herndon, VA- Remote in States Foxhole is registered to do business

Clearance: Active DoD Secret 

Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs. Our talented employee-owners provide agile, scalable services and solutions that solve operational gaps, operate critical systems, and protect and secure the enterprise – across the organization and around the world.

Support the Web Application Security Program (WASP) mission to ensure that security is integrated systematically and comprehensively throughout the Software Development Life Cycle (SDLC).

Job Description
  • Perform security reviews of web application architectures, APIs, and supporting infrastructure.
  • Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using industry-standard tools.
  • Conduct application spidering, fuzzing, and business logic abuse testing to identify vulnerabilities.
  • Execute Web Application Penetration Testing against modern frameworks (e.g., React, Angular, , Django, Flask, .NET Core).
  • Test APIs using REST and GraphQL fuzzing, schema validation, and security automation.
  • Identify and validate vulnerabilities such as:
  • OWASP Top 10
  • Business Logic flaws
  • API Security vulnerabilities (OWASP API Top 10)
  • Authentication and authorization weaknesses
  • Deserialization and injection flaws
  • Conduct manual exploit validation beyond automated tool output to reduce false positives.
  • Develop and maintain test automation scripts using frameworks like Burp Suite Extender API, ZAP scripting, and custom Python tools.
  • Integrate security testing into CI/CD pipelines using GitLab CI, GitHub Actions, Jenkins, or Azure DevOps.
  • Utilize SCA (Software Composition Analysis) tools to identify vulnerable dependencies (e.g., Snyk, Dependency-Check, Black Duck).
  • Implement the Common Weakness Scoring System (CWSS) and assist in Common Vulnerability Scoring System (CVSS) ratings for prioritization.
  • Generate technical reports and provide remediation guidance to developers, system owners, and ISSOs.
  • Provide monthly and annual program metrics including trends in vulnerability classes, remediation timelines, and residual risk.
Minimum Requirements
  • Active DoD Secret security clearance
  • 5 + years of progressive incident response experience
  • DoD IAT II required certification/s (one of the following):  CCNA-Security, CySA+ (CSA+), GICSP, GSEC, Security+ CE,  CND, SSCP, GWAPT, OSWE, eWPT
  • CSSP-AUrequired certification/s (one of the following): GSNA, CISA
  • Required Tools & Hands-On Skills

    • Web Security Testing & Automation: Burp Suite Pro, OWASP ZAP, Postman, Fiddler, mitmproxy.
    • SAST/DAST: Checkmarx, Fortify, Veracode, SonarQube, Acunetix, AppScan.
    • SCA (Software Composition Analysis): Snyk, OWASP Dependency-Check, Black Duck, Mend.
    • Fuzzing & Exploit Development: AFL, Peach Fuzzer, boofuzz.
    • API Security Testing: Postman, Insomnia, ReadyAPI, Burp Suite extensions for GraphQL/REST.
    • CI/CD Security Integration: GitLab CI, Jenkins, GitHub Actions, Azure DevOps with security plugins.
    • Containers & Cloud Security (preferred): Docker, Kubernetes, AWS Inspector, Prisma Cloud. 
Desired Experience/Certifications
  • Strong knowledge of the OWASP Top 10 and OWASP ASVS.
  • Familiarity with CWE, NIST 800-53/171, and DISA STIGs.
  • Hands-on experience with scripting languages (Python, Bash, PowerShell, JavaScript).
  • Familiarity with DevSecOps practices and secure coding guidelines.
  • Ability to communicate complex findings clearly to both technical and non-technical stakeholders.
More Information

Requirements of position:  Think analytically, effective verbal and written communication skills, make decisions, observe/remember details, interpret data, concentrate on tasks, adjust to change, handle stress/emotions.  Regular attendance, maintain work schedule, attend meetings, meet deadlines, keyboard/type, handle confidential information, use math/calculations, stay organized, operate office equipment, may direct others.   May be exposed to dust/dirt, humidity, and noise.

Foxhole Technology is an Equal Opportunity Employer and makes hiring decisions without regard to race, color, religion, sex (including pregnancy, childbirth and sexual orientation), national origin, age, disability, genetic information, military/veteran status, or any other protected class.



  • Smyrna, Georgia, United States Allied Universal Full time

    Overview Allied Universal, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace, you will be part of a team that contributes to a culture that positively impacts the communities and customers we serve. Job Description As...


  • Smyrna, Georgia, United States Allied Universal Full time $40,000 - $60,000 per year

    OverviewCompany Overview:Allied Universal, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace, you will be part of a team that contributes to a culture that positively impacts the communities and customers we serve. We...


  • Smyrna, Georgia, United States Novia Infotech Full time

    Oracle Integration Cloud (OIC) ConsultantLocation: Atlanta, GA / Smyrna, GA / Forest Park, GADuration: 12+ MonthsCompetencies: 8-10+ Years Experience RequiredDigital: PaaS - Oracle Integration CloudOracle Advanced Supply Chain PlanningPL/SQLMust Have Technical / Functional Skills:8-10 years of experience in multiple end-to-end Oracle Fusion implementation...


  • Smyrna, Georgia, United States Asurion Full time $60,000 - $100,000 per year

    Asurion is seeking an Executive Assistant/Legal Administrative Support to provide support for multiple attorneys and legal professionals. We are dedicated to finding a professional who possesses drive, strong communication skills, initiative, and a great attitude to manage day-to-day business activities that arise in Asurion's Legal Department. The candidate...


  • Smyrna, Georgia, United States PowerPlan, Inc. Full time

    OverviewA Senior Solution Architect in Professional Services, Platform organization plays a pivotal role in driving the success of PowerPlan's strategic and transformational programs within the energy industry. The position is responsible for project delivery, resource development, business development, and leading strategic projects and innovation...

  • EHS Manager

    2 weeks ago


    Smyrna, Georgia, United States DRiV Full time $80,000 - $120,000 per year

    DRiV Motorparts is a world leader in the international automotive aftermarket built from the combined strengths of Tenneco, Federal-Mogul and Öhlins with 31 of the best known and respected aftermarket brands, including 14 brands 100 years or older. Our colleagues throughout 25 countries around the world work as one team, driving advancements...

  • General Manager

    2 weeks ago


    Smyrna, Georgia, United States Nothing Bundt Cakes Full time $60,000 - $120,000 per year

    Benefits: 401(k)401(k) matchingBonus based on performanceDental insuranceEmployee discountsHealth insurancePaid time offVision insuranceThis position will begin with a (90) day training period before stepping into the full benefits and responsibilities associated with the General Manager role. During these (90) days, the candidate will be referred to as the...


  • Smyrna, Georgia, United States International SOS Government Medical Services Full time

    Company Description International SOS Government Medical Serivces, Inc. delivers customized medical and security risk management and wellbeing solutions to enable our clients to operate safely and effectively in environments far from home. Founded in 1984, we operate in 92 countries providing integrated medical solutions to organizations with international...

  • Assistant Manager

    1 day ago


    Smyrna, Georgia, United States Applebee's Full time

    2728 New Spring Road Smyrna, GA 30080Based in Pasadena, California, Dine Brands Global, Inc. (NYSE: DIN), through its subsidiaries, franchises restaurants under Applebee's Neighborhood Grill + Bar, IHOP and Fuzzy's Taco Shop brands. With over 3,500 restaurants combined in 18 countries and 354 franchisees as of December 31, 2023, Dine Brands is one of the...


  • Smyrna, Georgia, United States Collage Nursing and Home Care Partners, LLC Full time

    Collage Rehabilitation PartnersJob Description Position Title: Patient Account Specialist Reports To: Program Director FLSA Status: Exempt Job Summary This position is responsible for admissions processes as well as accounts receivable functions, including billing and collections for Collage Rehabilitation Partners. Essential Duties & FunctionsReceives and...