Senior Application Penetration Tester
Core
Conduct manual penetration testing of APIs, web applications, mobile applications, and thick-client applications, including threat modeling and business logic assessment.
Role type
Senior Application Penetration Tester
Builds
Security assessments for client engagements
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Manual penetration testing, API security, web application security, mobile application security, threat modeling, business logic assessment, architecture review, Burp Suite Pro, Netsparker, Checkmarx
Preferred skills
Ethical hacking certifications (GWAPT, CREST, OSWE, OSWA)
Technologies
REST, SOAP, Mobile Web API
Responsibilities
Conduct manual penetration testing of APIs, web applications, mobile applications, and thick-client applications; perform threat modeling and assess application business logic; review application architecture; demonstrate testing expertise to internal and external audiences; work independently on engagements with minimal oversight.
Seniority
Senior, hands-on IC