Penetration Tester
Job Description
Packetlabs is hiring a Penetration Tester for expert-level application security testing across multiple platforms.
Responsibilities
- Conduct penetration testing across web applications, mobile applications, thick clients, and APIs.
- Perform source code review and whitebox penetration testing to demonstrate real impact from application flaws.
- Carry out reverse engineering of mobile and thick client applications.
- When applicable, chain weaknesses to other environments, including cloud and on-prem AD infrastructure.
- Run SAST and DAST on enterprise, SaaS, and custom in-house applications.
- Use security scanners and apply validation/elimination techniques for false positives.
- Develop detailed findings documentation, including remediation-focused reports for both technical and executive audiences.
- Debrief testing results at both technical and executive levels.
- Apply an OWASP-informed approach across Web, API, Mobile, and AI/LLM.
Requirements
- Customer-first mentality.
- Strong communication skills with clients, project managers, and teammates.
- Ability to respond quickly and deliver work on time.
- Take pride in the quality of delivered results.
- Dig deeper into findings and continue testing until impact is proven.
- Comfort working through challenges and obstacles, not avoiding them.
- Experience adapting to a consulting-style environment with rapidly changing needs.
- Ongoing learning mindset, with awareness of your own skillset and willingness to improve.
- Self-motivated and dependable.
- Humble team approach; egos are not a fit for Packetlabs.
- Solid working knowledge of programming languages including: C, C#, Python, Objective-C, Java, JavaScript, SQL, and AngularJS.
- Familiarity with web services and data formats including: XML, JSON, SOAP, REST, AJAX.
- Understanding of AI/LLM weaknesses and flaws in applications.
- Extensive experience using an attack proxy such as Burp Suite.
- Professional qualifications (one or more): OSCP, OSWE, BSCP.
- OSCP or Burp is mandatory for this organization.
- Must be located in Florida.
- Minimum experience: 3 years.
- Education: graduate of a post-secondary college or university degree program.
Technologies
- C, C#, Python, Objective-C, Java, JavaScript, SQL, AngularJS
- XML, JSON, SOAP, REST, AJAX
- Burp Suite, SAST, DAST
- OSCP, OSWE, BSCP
- OWASP
Benefits
- Competitive compensation and growth opportunity
- Paid education and professional development reimbursement for certifications and technical growth
- Flexible work environment
- Paid volunteer day each year
- Paid Birthday day off
- Paid U.S. public holidays
- Fully remote within Texas or Florida
Additional Notes (At-Will Employment)
This position is at-will. This job posting does not constitute an employment contract or guarantee of continued employment.