Web App Penetration Tester

Overview

Remote
Depends on Experience
Contract - Independent
Contract - W2
Contract - 6 Month(s)
No Travel Required
Unable to Provide Sponsorship

Skills

API
Web Applications
Penetration Testing
Threat Modeling
Testing
Burp Suite

Job Details

Responsibilities:

• Perform manual Application penetration testing against API’s (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform threat modeling, evaluate application business logic, and perform application architecture reviews
• Ability to demonstrate application testing experience in real time via demos to both internal and external audiences
• Ability to perform objective based, abstract penetration testing engagements
• Ability to develop and exploit POCs
• Act independently in penetration testing engagements, with minimal oversight and guidance
• Engage with technical and non-technical audiences to articulate both testing processes, techniques and results; guide technical audiences on remediation options and assist clients in weighing those options

Qualifications:

• Minimum 5 years of recent experience in application penetration testing of API’s, web applications and mobile applications
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker
• Bachelor's degree from an accredited college/university or equivalent industry experience
• One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA

• Must be onshore

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.