Penetration Tester
Job Description
Deloitte Technology supports and protects Deloitte around the world through technology development and processes. In this onsite role in Hermitage, TN, you will deliver penetration testing services as part of Deloitte Global cyber services, combining technology and manual ingenuity to produce actionable results for customers.
This position also focuses on modern offensive security, including work across web, APIs, network, mobile, thick client, and AI/LLM penetration testing, with the opportunity to use AI and LLM-based tools to accelerate reconnaissance and improve testing workflows.
Responsibilities
- Execute penetration testing engagements, including Web Application Penetration Testing
- Execute penetration testing engagements, including Web Services and API Penetration Testing
- Execute penetration testing engagements, including AI/LLM Penetration Testing
- Execute Network Penetration Testing
- Execute Mobile Application Penetration Testing
- Execute Thick Client Penetration Testing
- Provide consultative guidance to customers on findings in a clear and actionable format, in writing and verbally
- Enhance and update testing methodologies, processes, and testing standards documentation
- Leverage AI and LLM-based tools and prompt engineering using established platforms and emerging frameworks to accelerate reconnaissance and generate or refine testing scripts
- Build, customize, and maintain AI-driven agents to automate recurring testing tasks
- Continuously validate the accuracy and reliability of self-developed AI tools, working to reduce hallucinations and false positives in vulnerability identification
- Evaluate and integrate emerging AI-assisted offensive security tooling into team methodology and playbooks
- Analyze and understand complex architecture designs
- Communicate the services and capabilities the group can facilitate for clients
Requirements
- Experience with Kali Linux or other dedicated penetration testing OS platforms
- Knowledge of common testing tools such as Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and others
- Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities
- Familiarity with AI models and frameworks from providers such as Anthropic and OpenAI; configuring tools like Obsidian and Ollama is a plus
- Working knowledge of one scripting language and familiarity with at least one software programming language and framework
- Demonstrated experience working with diverse stakeholders, preferably on a global multi-national basis
- Ability to manage concurrent initiatives and use effective judgment for prioritization and time management
- Strong written and verbal communication skills
- Must be a US Citizen
Technologies
- Kali Linux
- Burp Professional
- AMASS
- Metasploit
- Postman
- Swagger
- NMAP
- Qualys
- SQL Map
- OWASP Top 10
- Anthropic
- OpenAI
- Obsidian
- Ollama
Benefits
- Limited immigration sponsorship may be available.
Preferred Qualifications
- Certified Ethical Hacker (CEH)
- Offensive Certified Security Professional (OSCP)
- Any GIAC certification (GSEC, GWAB, GPEN, GMOB, GCPN)
- OWASP Application Security Top 10
- OWASP API Security Top 10
- OWASP Thick Client Top 10
- OWASP LLM Top 10
- MITRE ATT&CK Framework
- Cloud Service testing
- Reverse Engineering
- Static Application Security Testing (SAST)
- Dynamic Application Testing (DAST)
- Experience of agentic development and its application to support penetration testing