Senior Application Penetration Tester
Senior
Ai Enabled Security
Ai Security
Api Security
Application Security
Application Security Engineering
Application Security Strategy
Cloud Native Security
Container Security
Information Security
InfoSec
Llm Security
Offensive Security
Owasp
Owasp Top Ten
Penetration Testing
Security Assessment
Security Standards
Security Testing
Software Security
Vulnerability Assessment
Web Application Security
Job Description
Senior Application Penetration Tester focuses on planning and executing security testing across modern application types, then driving remediation visibility and risk reporting to technical and executive stakeholders.
Responsibilities
- Plan and conduct penetration tests for web, mobile (iOS & Android), APIs, cloud-native/containerized systems, and AI/LLM-integrated applications
- Assess AI/ML and generative AI features for risks including prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure using guidance aligned to OWASP Top 10 for LLM Applications and MITRE ATLAS
- Collaborate with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelines
- Evaluate cloud-native and containerized workloads and Infrastructure as Code for misconfigurations and weak security controls across AWS, Azure, GCP, Docker, and Kubernetes
- Test modern API architectures including REST, GraphQL, and gRPC, with attention to OAuth2, OIDC, and JWT authentication/authorization flaws and microservices-based applications
- Perform mobile application security testing and reverse engineering, including analysis for hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypass
- Own overall vulnerability remediation status for the global application portfolio and act as a primary contact for application teams on remediation
- Manage application risk rating processes and support timely risk scoring for new and changing applications
- Build and maintain dashboards and status reports for portfolio leads and CIOs, including follow-up on overdue vulnerabilities to meet compliance timelines
- Create clear, actionable penetration test reports and communicate findings and a remediation strategy to both technical and executive stakeholders
- Research emerging attack techniques and tooling, and drive automation and process improvements across the testing program
Requirements
- Prior experience managing Information Security projects
- Bachelor’s Degree in Computer Science, Engineering, or another Engineering or Technical discipline, or equivalent relevant experience
- Minimum 2 years of professional experience performing penetration testing for web application, API endpoint, and mobile (iOS & Android)
- Knowledge of prioritizing remediation activities with operational teams using risk ratings of vulnerabilities and assets
- Knowledge of vulnerability management standards, including CVE and CVSS
- Knowledge across network security, wireless security, application security, infrastructure hardening and security baselines, and web server and database security
- Knowledge of penetration testing principles, tools, and techniques
- Working experience with industry frameworks such as OWASP, OWASP API Security Top 10, OWASP Top 10 for Large Language Model (LLM) Applications, NIST, NIST AI Risk Management Framework, and MITRE ATT&CK
- Comfort working outside comfort zone with willingness to learn
- Excellent verbal and written communication skills
- Strong analytical skills
- Strong team player with ability to work independently
- Strong project management skills and ability to multi-task
- Self-motivated with strong initiative
- Knowledge of computer networking concepts and protocols and application security methodologies
- Skill in performing impact/risk assessments
- Familiarity with modern application architectures including cloud-native (AWS, Azure, GCP), containerized (Docker, Kubernetes), microservices, and API-first designs (REST, GraphQL, gRPC)
- Foundational understanding of AI/ML and generative AI security risks such as prompt injection, model manipulation, and sensitive data leakage is a plus
Technologies
- AWS, Azure, GCP, Docker, Kubernetes, Infrastructure as Code
- REST, GraphQL, gRPC, OAuth2, OIDC, JWT
- MLOps, CI/CD
- OWASP, OWASP API Security Top 10, OWASP Top 10 for Large Language Model (LLM) Applications, OWASP Top 10 for LLM Applications
- NIST, NIST AI Risk Management Framework, MITRE ATT&CK, MITRE ATLAS
- CVE, CVSS
- Kali Linux, Metasploit, Nmap, Burp Suite, OWASP ZAP, Santoku
- Genymotion, APKTool, JD-GUI, SQLMap, Semgrep, Snyk, Checkmarx, AppScan, Veracode
- Trivy, Grype, Prowler, ScoutSuite, Garak, PyRIT, OWASP ASVS
- OSCP, OSWE, GWAPT, GPEN, CEH, GCPN, CCSP
- LangChain, Semantic Kernel, AutoGen, RAG vector databases
Location: Philadelphia, PA (onsite)
Similar Jobs
J
J