Penetration Tester
Core
Perform penetration testing, source code review, and reverse engineering on web, mobile, thick client, and API applications to identify and prove the impact of security flaws.
Role type
Senior IC application security penetration tester
Builds
Security assessments and remediation reports for web, mobile, and API applications
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, source code review, whitebox testing, reverse engineering, SAST/DAST, OWASP knowledge, attack proxy usage, programming (C, C#, Python, Objective-C, Java, JavaScript, SQL), web services (XML, JSON, SOAP, REST, AJAX), AI/LLM vulnerability assessment
Preferred skills
3-5 years penetration testing/consulting experience, post-secondary degree, OSCP/OSWE/BSCP certification
Technologies
Burp Suite, AngularJS, SAST tools, DAST tools, OWASP frameworks
Responsibilities
Perform penetration testing on web/mobile/API/thick clients; conduct source code review and whitebox testing; reverse engineer mobile and thick client apps; develop detailed reports on findings and remediations; perform SAST and DAST on enterprise/SaaS applications; validate scanner results and eliminate false positives
Seniority
Mid-Senior, hands-on IC