Penetration Tester / AppSec Engineer
Core
Identifying and addressing security vulnerabilities in applications and systems through penetration testing and security assessments for clients.
Role type
Penetration Tester / Application Security Engineer
Builds
Security assessments and remediation guidance for client applications
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, Static application security testing (SAST), Dynamic application security testing (DAST), Code review, Risk analysis, Secure coding practices, Security policy design, Scripting (Python, JavaScript), Web application security knowledge, OWASP Top 10 expertise, Vulnerability assessment
Preferred skills
OSCP certification, CEH certification, GIAC (GWAPT) certification, Tool development
Technologies
Burp Suite, Metasploit, Nessus
Responsibilities
Conduct penetration testing on web, mobile, and network applications; Perform static and dynamic application security testing and code reviews; Identify and report security vulnerabilities with risk analysis; Collaborate with development teams to integrate secure coding practices; Develop and maintain security testing tools and documentation; Stay current with emerging security threats; Assist in designing application security policies and standards
Seniority
Mid-level, hands-on IC