Penetration Tester
Job Description
Deloitte offers an opportunity to support Global cyber services by delivering penetration testing work for member firms. You will combine hands-on testing with technology to help uncover risks across a wide range of application and infrastructure environments, including web, API, AI/LLM, network, mobile, and thick client targets.
This onsite role in Cincinnati, OH emphasizes practical impact: translating findings into clear, actionable guidance for customers while continuously improving testing methodologies and documentation. You will also use AI/LLM tools and prompt engineering to accelerate reconnaissance and improve testing scripts and automation.
Responsibilities
- Provide penetration testing services as part of the Global cyber services organization for member firms, using a mix of technology and manual ingenuity.
- Execute penetration testing engagements across:
- Web Application Penetration Testing
- Web Services / API Penetration Testing
- AI/LLM Penetration Testing
- Network Penetration Testing
- Mobile Application Penetration Testing
- Thick Client Penetration Testing
- Deliver consultative guidance on findings in clear, actionable writing and verbally to customers.
- Enhance and update testing methodologies, processes, and standards documentation.
- Leverage AI and LLM-based tools and prompt engineering to accelerate reconnaissance and generate or refine testing scripts, using both established platforms and emerging frameworks.
- Build, customize, and maintain AI-driven agents to automate recurring testing tasks.
- Continuously validate the accuracy and reliability of self-developed AI tools, working to reduce hallucinations and false positives in vulnerability identification.
- Evaluate and integrate emerging AI-assisted offensive security tooling into team methodology and playbooks.
- Analyze and understand complex architecture designs.
- Communicate the services and capabilities the group can facilitate to clients.
Requirements
- Experience with Kali Linux or other dedicated penetration testing OS platform.
- Working knowledge of common testing tools, including Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and others.
- Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities.
- Familiarity with AI models and frameworks from providers such as Anthropic and OpenAI, with experience configuring tools like Obsidian and Ollama as a plus.
- Working knowledge of one scripting language and familiarity with at least one software programming language and framework.
- Demonstrated experience working with diverse stakeholders, preferably in global multi-national environments.
- Ability to manage concurrent initiatives using sound judgment for prioritization and time management.
- Strong written and verbal communication skills.
- Must be a US Citizen.
Technologies
- Kali Linux
- Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map
- OWASP Top 10
- Anthropic, OpenAI, Obsidian, Ollama
- OWASP Application Security Top 10, OWASP API Security Top 10, OWASP Thick Client Top 10, OWASP LLM Top 10
- MITRE ATT&CK Framework
- Static Application Software Testing (SAST), Dynamic Application Testing (DAST)
Preferred
- Certified Ethical Hacker (CEH)
- Offensive Certified Security Professional (OSCP)
- Any GIAC certification (GSEC, GWAB, GPEN, GMOB, GCPN)
- OWASP Application Security Top 10, OWASP API Security Top 10, OWASP Thick Client Top 10, OWASP LLM Top 10
- MITRE ATT&CK Framework
- Cloud service testing
- Reverse Engineering
- Experience with agentic development and its application to support penetration testing
- Limited immigration sponsorship may be available