CybersecurityJobs.io
← Back to all jobs

Job Description

Delivery Senior Consultant, Penetration Tester role in Gilbert, AZ (hybrid) focused on evaluating the security of web applications, APIs, and related systems through hands-on testing and remediation guidance.

Responsibilities

  • Execute both manual and automated security testing of web applications, APIs, and supporting infrastructure.
  • Identify, validate, and document vulnerabilities, including items mapped to the OWASP Top 10.
  • Perform authenticated and unauthenticated testing across development, test, and production-like environments.
  • Evaluate application security controls such as authentication, authorization, session management, input validation, and encryption.
  • Produce clear, risk-based reports detailing technical findings, business impact, proof of concept, and remediation guidance.
  • Collaborate with developers, architects, and security teams to explain findings and support remediation efforts.
  • Retest remediated issues and verify closure of findings.
  • Contribute to security standards, testing methodologies, and internal knowledge sharing.
  • Maintain awareness of emerging threats, exploit techniques, and trends in application security.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
  • Ability to obtain and maintain the necessary clearance for the role.
  • Certifications such as OSCP, OSWE, GPEN, or CEH.
  • 2+ years of experience in web application focused penetration testing.
  • Strong understanding of web technologies including HTTP/S, REST APIs, JavaScript, cookies, headers, and sessions.
  • Experience identifying vulnerabilities such as SQL injection, XSS, CSRF, SSRF, IDOR, authentication flaws, and access control weaknesses.
  • Proficiency with testing tools such as Burp Suite, OWASP ZAP, Nmap, Postman, and similar tools.
  • Experience writing professional penetration test reports for technical and non-technical audiences.
  • Familiarity with OWASP Top 10, CWE, CVSS, and secure coding principles.

Delivery Center Location & Travel Requirements

  • Hybrid Work Model requiring residence within commutable distance to US Delivery Center locations (Gilbert, Lake Mary, Mechanicsburg) or Geo-Hub locations (Atlanta, Charlotte, Dallas, Houston, Philadelphia).
  • Co-location up to 30% of working time at an assigned office for projects, training, and related opportunities at Deloitte Delivery Center locations, Geo-Hub locations, approved sites, or project locations.
  • Travel up to 10% overnight for client or project purposes.
  • If relocation is necessary, complete the move within 12 weeks from the start date to reside within a commutable distance.
  • Must be legally authorized to work in the United States without employer sponsorship now or in the future.

Technologies

  • Burp Suite
  • OWASP ZAP
  • Nmap
  • Postman

Similar Jobs