CybersecurityJobs.io
← Back to all jobs

Job Description

Deloitte’s Global cyber services team is seeking a Penetration Tester to deliver practical security testing across a wide range of modern application and infrastructure surfaces. In this onsite role in Nashville, TN, you will execute penetration testing engagements and support customers with clear, actionable guidance on findings, while helping evolve testing methods through AI/LLM-enabled workflows.

Penetration testing engagements

  • Execute penetration testing engagements across web applications
  • Perform web services / API penetration testing
  • Conduct AI/LLM penetration testing
  • Carry out network penetration testing
  • Test mobile applications
  • Evaluate thick client applications through penetration testing

Consulting and methodology

  • Provide consultative guidance to customers on identified findings, delivered in writing and verbally in a clear and actionable format
  • Enhance and update testing methodologies, processes, and standards documentation
  • Analyze and understand complex architecture designs
  • Communicate the services and capabilities the group can facilitate for clients
  • Proactively evaluate and integrate emerging AI-assisted offensive security tooling into team methodology and playbooks

AI/LLM-assisted offensive security

  • Leverage AI and LLM-based tools and prompt engineering to accelerate reconnaissance and generate or refine testing scripts, using established platforms and emerging frameworks
  • Build, customize, and maintain AI-driven agents to automate recurring testing tasks
  • Continuously validate the accuracy and reliability of self-developed AI tools, working to reduce hallucinations and false positives in vulnerability identification

Required skills and experience

  • Experienced with Kali Linux or other dedicated penetration testing OS platforms
  • Knowledge of common testing tools, including Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and others
  • Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities
  • Familiarity with AI models and frameworks from providers such as Anthropic and OpenAI, and experience configuring tools like Obsidian and Ollama is a plus
  • Working knowledge of one scripting language and familiarity with at least one software programming language and framework
  • Demonstrated experience working with diverse stakeholders, preferably on a global multi-national basis
  • Ability to manage concurrent initiatives and use judgment in prioritization and time management
  • Strong written and verbal communication skills
  • Must be a US Citizen

Preferred qualifications

  • Certified Ethical Hacker (CEH)
  • Offensive Certified Security Professional (OSCP)
  • Any GIAC certification (GSEC, GWAB, GPEN, GMOB, GCPN)
  • OWASP Application Security Top 10, OWASP API Security Top 10, OWASP Thick Client Top 10, and OWASP LLM Top 10
  • MITRE ATT&CK Framework
  • Cloud service testing
  • Reverse Engineering
  • Static Application Software Testing (SAST) and Dynamic Application Testing (DAST)
  • Experience with agentic development and applying it to support penetration testing

Technologies

  • Kali Linux
  • Burp Professional
  • AMASS
  • Metasploit
  • Postman
  • Swagger
  • NMAP
  • Qualys
  • SQL Map
  • OWASP Top 10
  • Anthropic
  • OpenAI
  • Obsidian
  • Ollama

Similar Jobs