Job description
Job Description:
- Perform penetration testing of web applications, mobile applications, thick clients, and APIs
- Conduct source code review and whitebox penetration testing to prove the impact of application flaws
- Reverse engineer mobile and thick client applications
- Chain application flaws into cloud and on-premises Active Directory infrastructure where appropriate
- Develop detailed reports on findings and remediations for impactful findings
- Debrief findings at technical and executive levels
- Perform SAST and DAST on enterprise, SaaS, and custom in-house applications
- Use scanners and validate findings while eliminating false positives
Requirements:
- Solid working knowledge of C, C#, Python, Objective-C, Java, JavaScript, SQL, and AngularJS
- Familiarity with XML, JSON, SOAP, REST, and AJAX
- Understanding of AI/LLM weaknesses and application flaws
- Extensive experience using an attack proxy such as Burp Suite
- 3–5 years of penetration testing and consulting experience preferred
- At least two years of experience with information security-related tasks
- Professional qualification(s), such as OSCP, OSWE, or BSCP
- OSCP or Burp is mandatory for the organization
- Must be located in Florida
- Strong understanding of OWASP for Web, API, Mobile, and AI/LLM
- Experienced developer/application security tester
Benefits:
- Competitive compensation and pay for performance
- Employee growth and development
- Fully remote (in Florida)
first seen 2026-08-07 08:40:01 · last verified 2026-08-07 08:40:01
pentestcareers.com // breach the job market