Search

Senior Penetration Tester - Application Security

PublishedPublished: 6/14/2022
Technology

Job Description

Employment Type: Contract

\n

C2C: No C2C

\n

Sponsorship: No sponsorship available

\n


\n

Opportunity available for a Senior Penetration Tester with strong hands-on experience testing web applications and APIs in enterprise environments. The ideal candidate will have advanced Burp Suite experience and the ability to independently manage penetration testing engagements from scoping through reporting and remediation validation.

\n


\n

Key Responsibilities

\n

    \n
  • Execute end-to-end penetration tests, including scoping, exploitation, validation, reporting, and remediation support
  • \n

  • Perform web application and API security testing
  • \n

  • Identify and evaluate OWASP Top 10 and other application vulnerabilities
  • \n

  • Assess authentication, authorization, injection, and other security weaknesses
  • \n

  • Use Burp Suite, Nmap, and common exploitation frameworks
  • \n

  • Develop Python or Go scripts and automation to support testing workflows
  • \n

  • Document findings with actionable remediation guidance
  • \n

  • Partner with engineering teams to validate and remediate vulnerabilities
  • \n

  • Contribute to improving penetration testing processes and tooling
  • \n

\n


\n

Required Skills

\n

    \n
  • 5+ years of hands-on penetration testing experience
  • \n

  • Strong web application and API penetration testing experience
  • \n

  • Experience independently executing end-to-end penetration tests
  • \n

  • Strong understanding of application vulnerabilities
  • \n

  • Advanced Burp Suite experience
  • \n

  • Experience with Nmap and exploitation frameworks
  • \n

  • Python or Go scripting/automation experience
  • \n

  • Strong technical documentation and communication skills
  • \n

  • Experience working directly with engineering teams on remediation
  • \n

\n


\n

Strongly Preferred

\n

    \n
  • PCI penetration testing experience
  • \n

  • Mobile application, hardware/embedded systems, or third-party/vendor platform testing
  • \n

  • Bug bounty triage and validation experience
  • \n

  • Threat modeling experience
  • \n

  • Mentoring or technical guidance experience
  • \n

\n


\n

Nice to Have

\n

    \n
  • Advanced networking and system architecture knowledge
  • \n

  • Penetration testing automation/process improvement experience
  • \n

  • OSCP, OSCE, OSWE, CISSP, or similar certifications
  • \n

\n


\n

Qualifications

\n

    \n
  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent practical experience
  • \n

  • 7+ years of cybersecurity experience, with progressive penetration testing responsibilities
  • \n

\n


\n

Important: This is a W-2 opportunity only — no C2C.

\n


\n

ITR Group offers a competitive compensation and benefits package, including medical, dental, and 401(k) for eligible employees. The pay rate for this role is approximately 80-90 hourly. This range is an estimate and not a guarantee of compensation. The final compensation will be determined by factors such as experience, market trends, and specific job assignments. Discover more about how ITR Group connects top talent with leading client opportunities.

\n


\n

ITR Group is an Equal Opportunity Employer. We do not discriminate against applicants on the basis of their race, color, national origin, religion, creed, disability, age, sex, sexual orientation, gender identity, marital status, familial status, or status with regard to public assistance, or membership or activity in a local human rights commission.

\n


Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...