You will perform application security assessments and offensive security testing to evaluate technology vulnerabilities.
This role is remote.
Responsibilities
Perform manual web application assessments and code reviews to identify security-relevant issues.
Analyze internal and external threats, incorporating attacker tactics into offensive security testing.
Execute penetration testing tools, triage incidents, and manually reproduce findings with proof-of-concepts.
Prepare and present detailed technical reports on system security effectiveness and remediation concepts.
Mentor junior assessors in technical tradecraft and soft skills.
Required Skills
5 years of professional experience in pentesting, application security, or ethical hacking.
Expertise in SQL injection and XSS attacks without relying on automated tools.
Deep knowledge of at least 3 areas: security engineering, application architecture, authentication protocols, session management, applied cryptography, mobile frameworks, SSO, exploit automation, or RESTful web services.
Proficiency with Restful Web Services, SQL, Unix/Linux, and TCP/IP protocols.
Solid programming and debugging skills with ability to develop PoCs.
Experience in manual code reviews and understanding of network/web protocols.
Preferred Skills
CISSP, CEH, OSCP, OSWE, GPEN, or PenTest+ certifications.