CybersecurityJobs.io
← Back to all jobs

Job Description

NetSPI offers an on-site opportunity in Minneapolis, MN for a Senior Security Consultant focused on web application and API security testing. This role centers on hands-on assessments, delivering actionable reports, and advancing security best practices across diverse client environments. You will collaborate with experienced teams, mentor colleagues, and contribute to the ongoing evolution of NetSPI’s tools and methodologies. The culture emphasizes thoughtful collaboration, continuous learning, and meaningful impact on client security outcomes. The position requires an 8-hour workday with occasional evenings or weekends to meet project deadlines, and a travel footprint of up to 5-10% as needed.

Responsibilities

  • Conduct engagements on web applications and underlying APIs independently and provide technical oversight
  • Review reports for accuracy in technical oversight, perform weekly QA oversight, and provide mentoring support to others
  • Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture
  • Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes
  • Participate in development, implementation, and oversight of testing, delivery, and management strategies for key client accounts
  • Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations

Minimum Qualifications

  • Bachelor’s degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience
  • Minimum of 3-5 years of work experience in Penetration Testing
  • Familiarity with offensive tools based on applicable skillset (for example Kali Linux, Burp Suite, Metasploit, Nessus)
  • Familiarity with offensive and defensive IT concepts and protocols
  • Extensive understanding of the OWASP Top 10, MITRE ATT&CK framework, and various security frameworks
  • Working knowledge of Windows, Linux and MacOS operating systems internals
  • Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
  • Ability to work independently and as part of a team
  • Proficient communication skills, both written and verbal
  • Willingness to travel up to 5-10%
  • This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs

Preferred Qualifications

  • Ability to provide technical and QA oversight on web applications and underlying APIs
  • Experience in one or more of the following programming or scripting languages: Ruby, Python, Perl, C, C++, Java, and C#
  • Offensive cybersecurity certifications such as GXPN, GPEN, OSCP, GWAPT

Technologies

  • Kali Linux
  • Burp Suite
  • Metasploit
  • Nessus
  • Windows
  • Linux
  • MacOS
  • Ruby
  • Python
  • Perl
  • C
  • C++
  • Java
  • C#
  • OWASP Top 10
  • MITRE ATT&CK framework

Similar Jobs