Jr. Penetration Tester with WebAPI and Mobile Applications - Remote

Overview

Remote
$25+
Contract - Independent
Contract - W2

Skills

Penetration Tester with WebAPI and Mobile Application Security Testing

Job Details

Role: Penetration Tester with WebAPI and Mobile Application Security Testing

Location: 100% Remote

Duration: Long Term

Experience: 3-5 Years

Rate: $25hr. W2 All Inc.

Note:

We are seeking an experienced Penetration Tester with strong expertise in WebAPI, Web, and Mobile Application Security Testing. The ideal candidate will be highly skilled in manual penetration testing, threat modelling, and application architecture reviews, with the ability to communicate findings effectively to both technical and non-technical stakeholders.

Responsibilities:

  • Perform manual Application penetration testing against API s (REST/SOAP), Web Applications, Mobile applications, and thick client applications
  • Perform threat modelling, evaluate application business logic, and perform application architecture reviews
  • Ability to demonstrate application testing experience in real time via demos to both internal and external audiences
  • Ability to perform objective based, abstract penetration testing engagements
  • Ability to develop and exploit POCs
  • Act independently in penetration testing engagements, with minimal oversight and guidance
  • Engage with technical and non-technical audiences to articulate both testing processes, techniques and results; guide technical audiences on remediation options and assist clients in weighing those options

Qualifications:

  • Minimum three (3) years of recent experience in application penetration testing of API s, web applications, or mobile applications
  • Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
  • Experience with burp suite pro, and other app testing tools such as Netsparker
  • Bachelor's degree from an accredited college/university or equivalent industry experience
  • One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

About Floga technologies