Senior Penetration Tester (WebApp and Network)
Job Description
Support security validation for web applications and network environments through hands-on penetration testing and vulnerability discovery.
Responsibilities
- Perform thorough penetration tests targeting web applications to uncover security vulnerabilities.
- Use penetration testing tools and established methodologies to simulate real-world cyber attacks.
- Identify weaknesses and vulnerabilities in web applications using a mix of manual and automated testing approaches.
- Test and exploit common web application vulnerabilities, including SQL injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and others.
- Produce detailed penetration test reports documenting findings and recommendations for security improvements.
- Partner with development teams to advise on security best practices.
- Stay current on evolving cybersecurity threats and new testing methodologies.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- 5+ years of experience in penetration testing or security assessment.
- Relevant industry certifications, such as CEH, OSCP, or GIAC Web Application Penetration Tester (GWAPT).
- Strong working knowledge of web application technologies and protocols (including HTTP/HTTPS, HTML, JavaScript, etc.).
- Hands-on proficiency with tools such as Burp Suite, OWASP ZAP, Metasploit, and SQLMap.
- Experience working with known exploits and understanding their mitigation.
- Ability to analyze penetration test outcomes and communicate results effectively through reporting.
- Strong problem-solving and analytical skills.
- Excellent communication skills to collaborate with cross-functional teams.
Technologies & Skills
- HTTP/HTTPS, HTML, JavaScript
- Burp Suite, OWASP ZAP, Metasploit, SQLMap
- SQL injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF)
- Python, Ruby
Desirable Skills
- Experience with scripting or programming languages such as Python, JavaScript, or Ruby.
- Knowledge of network security and operating systems.
- Familiarity with cloud environments and container technologies.
Location: Charlotte, NC (remote). Job type: part time (1099 part-time positions available). Travel: possible. Compensation: USD 50 - 65 per hourly.
Similar Jobs
J