Security Consultant II (Web Application Penetration Tester)
RemoteUnited Kingdom
Job Summary
Conduct penetration testing engagements on web applications and underlying APIs, creating and delivering clear, actionable reports in diverse client environments. Research and develop innovative techniques, tools, and methodologies for penetration testing services while maintaining client-specific processes and reporting standards. Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations. This role requires a Bachelor's degree, 2-3 years of application penetration testing experience, and familiarity with offensive tools like Burp Suite and Metasploit. Travel up to 10% is required, with an 8-hour workday including occasional evenings or weekends. Join NetSPI, a leader in modern pentesting trusted by top U.S. banks and Fortune 500 companies, to help clients improve their security posture through deep dive testing and vulnerability prioritization.
Required Qualifications
- Bachelor's degree or higher
- Minimum of 2-3 years of work experience in application penetration testing
- Familiarity with offensive tools
- Familiarity with offensive and defensive IT concepts and protocols
- Extensive understanding of the OWASP Top 10 and various security frameworks
- Working knowledge of Windows, Linux and MacOS operating systems internals
- Ability to work independently and as part of a team
- Proficient communication skills, both written and verbal
- Willingness to travel up to 5-10%
- This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs
Desired Qualifications
- concentration in Computer Science, Engineering, Math, or IT
- Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
- Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)
- Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, CISSP, GWAPT)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.