Manual Application Penetration Tester (Web & API)

Remote • Posted 30 days ago • Updated 30 days ago
Contract Corp To Corp
Contract Independent
No Travel Required
Remote
$55/yr
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Penetration Testing
  • Web Applications
  • Burp Suite
  • Manual Testing
  • API
  • OAuth
  • ethical hacking

Summary

Job Title:

Manual Application Penetration Tester (Web & API)

Contract Type:

Contract


Role Overview

We are seeking experienced Manual Application Penetration Testers to perform in-depth security testing of web applications, APIs, and mobile applications. This role requires hands-on, offensive security expertise with a strong focus on manual exploitation, business logic testing, and real-world attack simulation.

The ideal candidate can independently execute penetration testing engagements, clearly articulate findings to both technical and non-technical audiences, and guide remediation efforts.


Key Responsibilities

  • Perform manual application penetration testing of:

    • Web applications
    • REST & SOAP APIs
    • Mobile applications (iOS/Android – nice to have)
    • Thick client applications (where applicable)
  • Conduct business logic testing, threat modeling, and application architecture reviews

  • Identify and exploit vulnerabilities including (but not limited to):

    • IDOR / BOLA
    • Authentication & authorization flaws
    • Session management issues
    • Injection flaws (SQLi, XSS, XXE, etc.)
    • Logic flaws missed by automated scanners
  • Perform objective-based and abstract penetration testing engagements

  • Develop and demonstrate proof-of-concept (PoC) exploits

  • Use Burp Suite Pro extensively for manual testing (Repeater, Intruder, Decoder, etc.)

  • Present findings via live demos, written reports, and client readouts

  • Clearly communicate risks, impact, and remediation guidance

  • Work independently with minimal oversight while meeting delivery timelines


Required Qualifications

  • 5+ years of recent experience in manual application penetration testing

  • Strong experience testing:

    • Web applications
    • APIs (REST / SOAP)
  • Hands-on expertise with Burp Suite Pro

  • Proven ability to perform manual exploitation (not scanner-only testing)

  • Experience communicating results to both technical and non-technical stakeholders

  • Ability to lead remediation discussions and retesting efforts

  • Bachelor’s degree in Computer Science, Engineering, or equivalent industry experience


Preferred Qualifications

  • Mobile application penetration testing (iOS / Android)

  • Experience with tools such as:

    • Netsparker
    • OWASP ZAP
    • Postman / SoapUI
  • Experience with OAuth, JWT, and modern authentication mechanisms

  • Ethical hacking certifications (preferred, not required):

    • GWAPT
    • OSWE
    • OSWA
    • CREST

Nice-to-Have Experience

  • Threat modeling frameworks (STRIDE, PASTA, etc.)

  • Secure SDLC / DevSecOps exposure

  • Client-facing consulting or enterprise security engagements

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91017409
  • Position Id: 8883384
  • Posted 30 days ago

Company Info

About HCP ONE LLC

We have an exceptional team. Each of our consultants offers specific subject matter expertise in industries, functional areas, and global and local markets.

Innovation

We have the courage to invent and champion unconventional solutions to problems.

Excecution

We have a high hit ratio and absolutely razor-sharp execution.

Vision

"To be a premier international Human Capital Solutions firm defined by Character, Courage, and Competence, serving as a trusted partner in Executive Search and IT Staffing globally."

Mission

"To help clients across a range of industries build boards and executive leadership teams that can capitalize on digital transformation, globalization, and other trends."

Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs