Penetration Tester
Job Description
Deloitte Global cyber services is seeking a Penetration Tester to execute penetration testing engagements across multiple technology domains and deliver consultative guidance on findings. You will work with AI and LLM-based tools, apply prompt engineering to accelerate reconnaissance and testing automation, and help strengthen team methodologies and playbooks through continuous validation of tool accuracy.
Location: San Antonio, TX (onsite)
What you’ll do
- Execute penetration testing engagements, including Web Application Penetration Testing
- Execute penetration testing engagements, including Web Services / API Penetration Testing
- Execute AI/LLM Penetration Testing efforts using AI-assisted approaches
- Run Network Penetration Testing engagements
- Perform Mobile Application Penetration Testing
- Conduct Thick Client Penetration Testing
Across engagements, you will provide consultative guidance to customers by presenting findings in a clear and actionable manner, both in writing and verbally. You will also enhance and update testing methodologies, processes, and standards documentation.
AI-assisted testing and automation
- Use AI and LLM-based tools and prompt engineering to accelerate reconnaissance and generate or refine testing scripts
- Build, customize, and maintain AI-driven agents to automate recurring testing tasks
- Continuously validate the accuracy and reliability of self-developed AI tools, actively working to reduce hallucinations and false positives in vulnerability identification
- Evaluate and integrate emerging AI-assisted offensive security tooling into team methodology and playbooks
You will also analyze and understand complex architecture designs, and effectively communicate the services and capabilities the group can facilitate for clients.
Requirements
- Experience with Kali Linux or another dedicated Penetration Testing OS platform
- Knowledge of common testing tools such as Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and others
- Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities
- Familiarity with AI models and frameworks from providers such as Anthropic and OpenAI; configuring tools like Obsidian and Ollama is a plus for supporting other workflows
- Working knowledge of one scripting language
- Familiarity with at least one software programming language and framework
- Demonstrated experience working with diverse stakeholders, preferably on a global multi-national basis
- Ability to manage concurrent initiatives with effective judgment for prioritization and time management
- Strong written and verbal communication skills
- Must be a US Citizen
Technologies
- Kali Linux
- Burp Professional
- AMASS
- Metasploit
- Postman
- Swagger
- NMAP
- Qualys
- SQL Map
- OWASP Top 10
- Anthropic
- OpenAI
- Obsidian
- Ollama
Preferred
- Certified Ethical Hacker (CEH)
- Offensive Certified Security Professional (OSCP)
- Any GIAC certification (GSEC, GWAB, GPEN, GMOB, GCPN)
- OWASP Application Security Top 10
- OWASP API Security Top 10
- OWASP Thick Client Top 10
- OWASP LLM Top 10
- MITRE ATT&CK Framework
- Cloud Service testing
- Reverse Engineering
- Static Application Software Testing (SAST)
- Dynamic Application Testing (DAST)
- Experience of Agentic development and its application to support penetration testing