Ethical Hacker / Penetration Tester Principal
Application Security
Cybersecurity Tools
DevSecOps
Dynamic Application Security Testing
Ethical Hacking
Exploit Development
Information Security
InfoSec
Metasploit
Offensive Security
Penetration Testing
Pentesting Tools
Security
Security Assessment
Security Automation
Security Testing
Software Security
Vulnerability Assessment
Job Description
MKS2 Technologies is seeking an Ethical Hacker / Penetration Tester Principal to help secure a large-scale enterprise application environment. The role focuses on identifying, exploiting, assessing, and remediating vulnerabilities in Java-based applications and supporting infrastructure, in partnership with teams across the SDLC and DevSecOps lifecycle.
Location and Schedule
- Location: New York, NY (Hybrid)
- Work pattern: Remote with travel to Albany, NY twice per month (two trips per month)
- Job Type: Full-Time
- Program: NYSoH
- Hours: 40 hours per week
Salary
- Compensation: USD 120,000 per year
Key Responsibilities
- Perform penetration testing and vulnerability assessments for Java applications, APIs, and supporting infrastructure.
- Execute manual and automated security testing to uncover application vulnerabilities.
- Develop and run custom exploits to model real-world attacker behaviors.
- Review application architecture and source code to identify security risks and likely attack vectors.
- Collaborate with development teams to integrate security earlier in the SDLC.
- Work with QA and automation teams to incorporate security testing into release processes.
- Review source code and provide guidance aligned with secure remediation practices.
- Assess browser tokens, session management, caching, and authentication mechanisms.
- Test exploitation opportunities by manipulating URLs, query parameters, browser data, and application workflows.
- Support incident response activities related to security vulnerabilities and published CVE information.
- Create detailed reports covering findings, risk levels, business impact, and remediation recommendations.
- Deliver security findings to both technical and non-technical stakeholders.
- Contribute to security standards, policies, and secure development practices.
- Stay current on emerging threats, attack techniques, and industry best practices.
- Use methodologies aligned with MITRE ATT&CK and OWASP guidelines.
Required Qualifications
- Education: Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related technical field
- Experience: Minimum of 6 years of software development and security experience
- Prior experience in a DevSecOps, Application Security, Security Engineering, or Penetration Testing role
- Strong hands-on Java development experience
- Experience supporting large-scale enterprise applications
- Knowledge of secure coding principles and application security best practices
- Experience performing penetration testing against web applications and services
- Strong understanding of OWASP Top 10 vulnerabilities and mitigation techniques
- Experience using security testing tools, including: Burp Suite, Metasploit, web proxy tools, and vulnerability assessment platforms
- Experience with Static and Dynamic Application Security Testing (SAST/DAST), including: Fortify on Demand (SAST) and Fortify on Demand (DAST)
- Knowledge of web vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), Authentication & Authorization Flaws, Session Management Vulnerabilities, and API Security Risks
- Strong understanding of cryptography and secure communications protocols (SSL/TLS)
- Excellent analytical, troubleshooting, and problem-solving skills
- Strong written and verbal communication abilities
- Demonstrated professionalism, ethics, and confidentiality
Preferred Qualifications
- OSCP (Offensive Security Certified Professional)
- GWAPT (GIAC Web Application Penetration Tester)
- GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)
- GPEN (GIAC Penetration Tester)
- LPT (Licensed Penetration Tester)
- CEH (Certified Ethical Hacker)
- CISSP (Certified Information Systems Security Professional)
- Experience with Python, Bash, or other scripting languages
- Experience performing secure code reviews for Java applications
- Knowledge of cloud security testing methodologies
- Mobile application penetration testing experience
- Experience conducting API security assessments
- Familiarity with HIPAA and regulated environments
- Knowledge of vulnerability management and CVE remediation processes
Technologies and Methodologies
- Java
- Burp Suite
- Metasploit
- Fortify on Demand (SAST)
- Fortify on Demand (DAST)
- MITRE ATT&CK Framework
- OWASP
- SSL/TLS
- SQL Injection, Cross-Site Scripting (XSS)
- Authentication & Authorization Flaws
- Session Management Vulnerabilities
- API Security Risks
- SAST/DAST
- DevSecOps, API Security
- Threat Modeling, Risk Assessment
Security Clearance
- Clearance Required: None
- Citizenship Requirement: None
Why Join MKS2 Technologies
- Work on mission-critical enterprise applications.
- Collaborate with a highly skilled cybersecurity team.
- Influence secure development practices across large-scale environments.
- Gain exposure to advanced security testing technologies and methodologies.
- Make a direct impact on application security and cyber resilience.