CybersecurityJobs.io
← Back to all jobs

Job Description

Deloitte Global cyber services is looking for a Penetration Tester to deliver penetration testing services as part of its cybersecurity team. This onsite role in Kansas City, MO focuses on executing assessments across multiple environments, including web, API, AI/LLM, network, mobile, and thick client engagements, while leveraging AI/LLM capabilities to improve efficiency in reconnaissance and testing.

What you’ll do

  • Execute penetration testing engagements including Web Application Penetration Testing
  • Conduct Web Services / API Penetration Testing for application and service interfaces
  • Perform AI/LLM Penetration Testing using AI/LLM approaches to support testing activities
  • Run Network Penetration Testing engagements against network-facing systems
  • Deliver Mobile Application Penetration Testing assessments
  • Execute Thick Client Penetration Testing where applicable
  • Provide consultative guidance to customers on findings in a clear and actionable manner, delivered both in writing and verbally
  • Enhance and update testing methodologies, processes, and standards documentation
  • Use AI and LLM-based tools and prompt engineering to accelerate reconnaissance and generate or refine testing scripts
  • Build, customize, and maintain AI-driven agents to automate recurring testing tasks
  • Continuously validate the accuracy and reliability of self-developed AI tools, working to reduce hallucinations and false positives in vulnerability identification
  • Evaluate and integrate emerging AI-assisted offensive security tooling into team methodology and playbooks
  • Analyze and understand complex architecture designs
  • Communicate the services and capabilities the group can facilitate for clients

Required qualifications

  • Experience with Kali Linux or another dedicated penetration testing OS platform
  • Knowledge of common testing tools such as Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQLMap, and others
  • Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities
  • Familiarity with AI models and frameworks from providers such as Anthropic and OpenAI, plus experience configuring tools like Obsidian and Ollama is a plus for supporting other workflows
  • Working knowledge of one scripting language and familiarity with at least one software programming language and framework
  • Demonstrated experience working with diverse stakeholders, preferably on a global multi-national basis
  • Ability to manage concurrent initiatives, using sound judgment for prioritization and time management
  • Strong written and verbal communication skills
  • Must be a US Citizen

Technologies you may work with

  • Kali Linux
  • Burp Professional
  • AMASS
  • Metasploit
  • Postman
  • Swagger
  • NMAP
  • Qualys
  • SQL Map
  • Anthropic
  • OpenAI
  • Obsidian
  • Ollama
  • OWASP Top 10
  • AI/LLM
  • Prompt engineering

Team context

Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world.

Preferred

  • Certified Ethical Hacker (CEH)
  • Offensive Certified Security Professional (OSCP)
  • Any GIAC certification (GSEC, GWAB, GPEN, GMOB, GCPN)
  • OWASP Application Security Top 10
  • OWASP API Security Top 10
  • OWASP Thick Client Top 10
  • OWASP LLM Top 10
  • MITRE ATT&CK Framework
  • Cloud service testing
  • Reverse engineering
  • SAST
  • DAST
  • Experience of agentic development and applying it to support penetration testing

Similar Jobs