Penetration Tester
Job Description
Amatriot Group, LLC is seeking a Penetration Tester focused on Java application security. This onsite role in Rensselaer, NY involves identifying vulnerabilities, validating exploitation paths, and supporting remediation through clear technical reporting and collaboration across development and testing teams.
Role Overview
The Penetration Tester will assess Java applications and related infrastructure by applying both automated and manual techniques. Work includes vulnerability discovery, exploit validation, incident support for Java-related issues, and ongoing alignment with current published NIST CVEs. Familiarity with the MITRE ATT&CK Framework is expected to structure testing and adversary emulation approaches.
Key Responsibilities
- Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
- Identify security flaws in Java code using automated and manual methods.
- Create and use custom exploits to test application security and simulate attacker tactics.
- Manipulate URLs, query parameters, and application browser data to find penetration avenues.
- Validate and assess browser tokens, cache manipulation, and differences between production and non-production architecture.
- Assist in responding to security incidents related to Java vulnerabilities and relevant published NIST CVEs.
- Partner with development teams to understand application architecture and identify security weaknesses early in the lifecycle.
- Coordinate with testing teams to integrate security testing using both manual and automated methods.
- Provide guidance on secure coding and vulnerability remediation.
- Help improve secure development lifecycle processes.
- Contribute to security policies for Java development and deployment.
- Document and report findings with technical details, risk assessments, and recommended solutions.
- Communicate results and recommendations to both technical and non-technical stakeholders.
- Stay current on Java security threats and best practices.
- Apply familiarity with the MITRE ATT&CK Framework.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- Minimum 6 years of development or security experience. [Required]
- Experience in penetration testing or ethical hacking with a focus on Java application security.
- Experience using penetration testing tools such as Burp Suite and Metasploit.
- Familiarity with Fortify on Demand (SAST and DAST).
- Strong knowledge of Java programming and Java security practices.
- Scripting experience.
- Proficiency in web application security principles, including OWASP.
- Knowledge of common web vulnerabilities such as SQL injection and cross-site scripting, including exploit techniques.
- Strong understanding of cryptography and secure communication protocols including SSL/TLS.
- Excellent problem-solving and analytical skills.
- Strong communication skills.
- High ethical standards and confidentiality.
- Familiarity with the MITRE ATT&CK Framework.
Preferred Qualifications
- Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or other industry security certifications.
- Experience with scripting languages, such as Python or Bash.
- Experience with secure code review for Java.
- Familiarity with cloud security testing.
- Experience with mobile application penetration testing.
- Knowledge of regulations such as HIPAA.
- Experience with API testing.
Technologies and Frameworks
- Java
- Burp Suite
- Metasploit
- Fortify on Demand (SAST and DAST)
- OWASP
- MITRE ATT&CK Framework
- SQL injection
- cross-site scripting
- SSL/TLS
- NIST CVEs
Compensation and Job Details
- Target salary range: $90,000 - $105,000 per year
- Job type: Full-Time
- Location: Albany, NY (onsite)
- Security clearance: None
Similar Jobs
J