Penetration Tester
$90,000–$105,000 year
On-siteRensselaer, New York, United States
Job Summary
Conduct penetration tests and vulnerability assessments for Java applications and infrastructure, identifying security flaws using automated and manual methods. Create custom exploits to simulate attacker tactics, manipulate URLs and browser data, and validate tokens and cache mechanisms. Collaborate with development teams to integrate security testing, provide guidance on secure coding, and contribute to security policies. Clearly document findings with technical details and risk assessments, communicating recommendations to technical and non-technical staff while assisting in incident responses related to Java vulnerabilities and NIST CVEs. Stay updated on Java security threats and apply familiarity with the MITRE ATT&CK Framework.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field
- Minimum of 6 years of development or security experience
- Experience in penetration testing or ethical hacking with a focus on Java application security
- Experience with penetration testing tools such as Burp Suite and Metasploit
- Familiarity with Fortify on Demand SAST and DAST tools
- Strong knowledge of Java programming and Java security practices
- Scripting experience
- Proficiency in web application security principles, including OWASP
- Knowledge of common web vulnerabilities, including SQL injection and cross-site scripting, and exploit techniques
- Strong understanding of cryptography and secure communication protocols, including SSL/TLS
- Excellent problem-solving and analytical skills
- Strong communication skills
- High ethical standards and confidentiality
- Familiarity with the MITRE ATT&CK Framework
Desired Qualifications
- Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or other industry security certifications
- Experience with scripting languages, such as Python or Bash
- Experience with secure code review for Java
- Familiarity with cloud security testing
- Experience with mobile application penetration testing
- Knowledge of regulations such as HIPAA
- Experience with API testing
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.