CybersecurityJobs.io
← Back to all jobs

Job Description

As a Penetration Tester, you will execute comprehensive security assessments across the organization’s web applications and help strengthen the overall web application security posture. The role includes vulnerability discovery and documentation, remediation support, security control input, and analysis activities spanning incidents, forensics, and audit readiness.

Key Responsibilities

  • Perform thorough and comprehensive penetration testing on all web applications within the organization.
  • Identify, document, and track potential vulnerabilities and weaknesses in web applications.
  • Provide detailed, actionable remediation recommendations for vulnerabilities discovered during testing.
  • Partner with cross-functional teams to prioritize and support remediation efforts.
  • Maintain current knowledge of web application security threats and mitigation techniques.
  • Develop and maintain standard operating procedures and best practices for web application security testing.
  • Communicate security risks and findings to management and relevant stakeholders in a clear and concise manner.
  • Work with developers to support secure coding practices.
  • Contribute to the design and implementation of web application security controls and measures.
  • Research and test new web application security tools and technologies.
  • Coordinate with external vendors and partners to help ensure their web applications meet security standards.
  • Train and mentor junior team members on web application security best practices.
  • Monitor and analyze web application security logs and reports.
  • Continuously improve and enhance the organization’s web application security posture.
  • Adhere to company policies and procedures related to web application security.
  • Analyze attack trends and correlate logs across systems to identify advanced threats.
  • Enhance monitoring processes to improve detection speed, supporting compliance with security frameworks and regulatory standards.
  • Conduct root cause analysis, create incident response plans, and implement disaster recovery measures to reduce business disruption.
  • Undertake forensic analysis using advanced analytics tools and implement mitigation measures aligned with compliance requirements.
  • Liaise with cross-functional teams, external vendors, and auditors to support compliance with security frameworks.
  • Maintain audit documentation, ensuring accuracy while implementing processes that support audit readiness and continuous compliance.
  • Assist in creating and delivering cybersecurity awareness sessions, including guidance on phishing and malicious emails.

Requirements

  • Extensive experience in web application security testing techniques and tools, including OWASP Top 10, Burp Suite, and Kali Linux.
  • Knowledge of industry regulations and compliance standards, including PCI DSS, HIPAA, and ISO 27001.
  • Proven track record identifying and exploiting vulnerabilities in complex web applications, including Cross-Site Scripting (XSS), SQL Injection, and Session Hijacking.
  • Strong understanding of web development languages and frameworks, including HTML, CSS, JavaScript, and AngularJS.
  • Ability to communicate technical findings and recommendations to non-technical stakeholders, including management and development teams.
  • Penetration Testing (PT).

Location and Compensation

Location: Minneapolis, MN (remote)
Salary: USD 60,000 - 135,000 per year
Minimum experience: 5 years

Relevant Technologies

OWASP Top 10, Burp Suite, Kali Linux, PCI DSS, HIPAA, ISO 27001, Cross-Site Scripting (XSS), SQL Injection, Session Hijacking, HTML, CSS, JavaScript, AngularJS, phishing and malicious emails

Benefits

  • Full range of medical and dental benefits options
  • Disability insurance
  • Paid time off (inclusive of sick leave)
  • Other paid and unpaid leave options

Similar Jobs