Application Pen Tester (W2)

Hybrid in Charlotte, NC, US • Posted 1 day ago • Updated 1 day ago
Full Time
No Travel Required
Hybrid
$60 - $65/yr
Company Branding Image
Fitment

Dice Job Match Score™

👾 Reticulating splines...

Job Details

Skills

  • OSCP
  • Defect Analysis
  • Conflict Resolution
  • API QA
  • OWASP
  • PCI DSS
  • Regulatory Compliance
  • Testing
  • Penetration Testing
  • Scripting
  • Continuous Improvement
  • Authorization
  • Test Methods
  • Manual Testing
  • Problem Solving
  • WebInspect
  • Web API

Summary

Title: Application Pen Tester
Duration: 12-month
Location:  Charlotte NC/Hybrid

Visa: USC
W2 Role  

 

Other locations: Dallas, Minneapolis, Chandler, Des Moines, Columbus, Raleigh, San Antonio

 

 

Client is seeking an Application Pen Tester to identify, validate, and exploit security vulnerabilities through hands-on, manual testing across a broad range of application technologies. Browser-based/web and API testing are required, along with experience in one or more of the following: mobile, mainframe, or thick client testing. Successful candidates will have demonstrable, real-world manual penetration testing experience and be comfortable going beyond automated scanner output to reproduce, validate, and investigate findings. Success in this role means delivering high-confidence, reproducible vulnerabilities with clear evidence and practical remediation guidance, and partnering with application teams to drive timely fixes.

 

In this role, you will:

  • Conduct application penetration testing across browser-based/web applications, APIs, and mobile applications (and where applicable mainframe and thick client applications) using primarily manual techniques supplemented by automated tools; include authentication/authorization testing and business-logic abuse cases where applicable
  • Configure and tune automated tools to support testing, improve coverage, and accelerate discovery (as a complement to manual testing)
  • Perform deep defect analysis by reproducing, validating, and safely demonstrating impact (including chained attack paths when applicable); triage and disposition false positives from automated tooling
  • Produce clear, reproducible technical reports with evidence (steps to reproduce, impacted components/endpoints, and risk/impact) and practical remediation guidance
  • Collaborate with application and security teams to ensure shared understanding of defects, prioritization, and remediation paths; support defect walkthroughs and follow-up questions as needed
  • Support continuous improvement of testing methodologies and processes leveraging industry standards and best practices
  • Collaborate with other members of the team to share knowledge and complete peer reviews of reports
  • Communicate findings and risk clearly to technical and non-technical stakeholders, support readouts, status updates, and remediation Q&A

 

Required Qualifications:

  • 2+ years of Cybersecurity Research experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 2+ years of hands-on application penetration testing experience (manual testing required), beyond reviewing/validating automated scanner results
  • 2+ years of Dynamic Application Security Testing (DAST) experience, including tool configuration/tuning and manual verification of findings

 

Desired Qualifications:

  • Advanced experience with testing tools such as Burp Suite, Invicti, WebInspect, and Fiddler (and applying them to web, API, mobile, and thick client testing as applicable)
  • Strong knowledge of application security and common vulnerabilities (OWASP Top 10)
  • Experience with scripting and automation (e.g., Python, Shell)
  • Knowledge of security best practices and compliance standards (e.g., PCI DSS, GDPR)
  • Excellent communication skills and the ability to collaborate effectively with cross-functional teams
  • Strong problem-solving and analytical skills
  • Demonstrated knowledge of AI/ML-enabled applications and common security risks (for example, prompt injection, sensitive data exposure, and insecure integrations)
  • Security certifications such as OSCP, BSCP, GWAPT, GPEN, GXPN or equivalent are a plus

Thanks & Regards.

 

Aviral Sapra

Voto Consulting LLC

Direct #:

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91014022
  • Position Id: 8994682
  • Posted 1 day ago

Company Info

About Voto Consulting LLC

Who we are & What we do

Voto is new era technology enabler which aims to revolutionize digital transformation for enterprises and technology providers by delivering seamless customer experiences, business efficiency and actionable insights. We do this by leveraging a spectrum of disruptive technologies such as: artificial intelligence, blockchain, cloud, digital process automation, internet of things, robotics/drones, security, virtual/augmented reality, etc,

Agility is in our DNA that enhances our capabilities span digital solutions, infrastructure, product engineering and security. We deliver these services across industry sectors such as automotive, BFSI, consumer packaged goods, e-commerce, Edu-Tech, engineering R&D, hi-tech, manufacturing, retail, and travel/transportation/hospitality.

Recognized as one of the fastest-growing IT services firms globally, Voto is delivering solutions across North America, Europe, Middle East, and APAC countries.

Voto Consulting LLC is currently accepting resumes for a variety of positions. Please review the database of positions that we are seeking to fill and contact us for additional information about any specific opportunity.

About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs