Principal Penetration Tester (9 Month FTC)
Core
Senior penetration tester focusing on application security testing (70%) and offensive security activities (30%) to improve security depth and support purple team operations.
Role type
Principal Penetration Tester (Application Security & Offensive Security)
Builds
Security assurance for modern applications, APIs, backend services, and cloud-hosted workloads
Domain
Cybersecurity, Application Security, Offensive Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security testing, Penetration testing, API security, Cloud security (AWS), Binary analysis, OS exploitation, Threat modeling, SAST/DAST analysis, Authentication/Authorization testing
Preferred skills
Purple team development, Adversary informed assessments, ATT&CK aligned testing, Microservice architecture knowledge
Technologies
AWS, Spring Boot, RESTful APIs, Containerized environments, SAST tools, DAST tools
Responsibilities
Lead advanced penetration testing across web applications, APIs, and backend services; Assess Java-based backend systems and microservice architectures; Test authentication, authorization, and session handling; Carry out security testing in cloud and containerized environments; Review SAST/DAST outputs to prioritize risks; Support threat modeling and design reviews; Provide risk-based sign-off for releases.
Seniority
Principal, hands-on IC