CybersecurityJobs.io
← Back to all jobs

Job Description

Deloitte offers an opportunity to support Global cyber services by delivering penetration testing work for member firms. You will combine hands-on testing with technology to help uncover risks across a wide range of application and infrastructure environments, including web, API, AI/LLM, network, mobile, and thick client targets.

This onsite role in Cincinnati, OH emphasizes practical impact: translating findings into clear, actionable guidance for customers while continuously improving testing methodologies and documentation. You will also use AI/LLM tools and prompt engineering to accelerate reconnaissance and improve testing scripts and automation.

Responsibilities

  • Provide penetration testing services as part of the Global cyber services organization for member firms, using a mix of technology and manual ingenuity.
  • Execute penetration testing engagements across:
    • Web Application Penetration Testing
    • Web Services / API Penetration Testing
    • AI/LLM Penetration Testing
    • Network Penetration Testing
    • Mobile Application Penetration Testing
    • Thick Client Penetration Testing
  • Deliver consultative guidance on findings in clear, actionable writing and verbally to customers.
  • Enhance and update testing methodologies, processes, and standards documentation.
  • Leverage AI and LLM-based tools and prompt engineering to accelerate reconnaissance and generate or refine testing scripts, using both established platforms and emerging frameworks.
  • Build, customize, and maintain AI-driven agents to automate recurring testing tasks.
  • Continuously validate the accuracy and reliability of self-developed AI tools, working to reduce hallucinations and false positives in vulnerability identification.
  • Evaluate and integrate emerging AI-assisted offensive security tooling into team methodology and playbooks.
  • Analyze and understand complex architecture designs.
  • Communicate the services and capabilities the group can facilitate to clients.

Requirements

  • Experience with Kali Linux or other dedicated penetration testing OS platform.
  • Working knowledge of common testing tools, including Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and others.
  • Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities.
  • Familiarity with AI models and frameworks from providers such as Anthropic and OpenAI, with experience configuring tools like Obsidian and Ollama as a plus.
  • Working knowledge of one scripting language and familiarity with at least one software programming language and framework.
  • Demonstrated experience working with diverse stakeholders, preferably in global multi-national environments.
  • Ability to manage concurrent initiatives using sound judgment for prioritization and time management.
  • Strong written and verbal communication skills.
  • Must be a US Citizen.

Technologies

  • Kali Linux
  • Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map
  • OWASP Top 10
  • Anthropic, OpenAI, Obsidian, Ollama
  • OWASP Application Security Top 10, OWASP API Security Top 10, OWASP Thick Client Top 10, OWASP LLM Top 10
  • MITRE ATT&CK Framework
  • Static Application Software Testing (SAST), Dynamic Application Testing (DAST)

Preferred

  • Certified Ethical Hacker (CEH)
  • Offensive Certified Security Professional (OSCP)
  • Any GIAC certification (GSEC, GWAB, GPEN, GMOB, GCPN)
  • OWASP Application Security Top 10, OWASP API Security Top 10, OWASP Thick Client Top 10, OWASP LLM Top 10
  • MITRE ATT&CK Framework
  • Cloud service testing
  • Reverse Engineering
  • Experience with agentic development and its application to support penetration testing
  • Limited immigration sponsorship may be available

Similar Jobs