Penetration Tester || Hybrid onsite || Dallas, TX/Tampa, FL/Jersey city, NJ
Job description
We are currently looking to hire a [Penetration Tester] and we believe your skills and expertise are a better match for this role.
We are seeking an experienced and outstanding for one of our esteemed clients. Kindly have a look at the below JD and reach us with your updated & best time to connect.
Role: Penetration Tester
Location: Tampa, FL/Dallas, TX/Jersey city, NJ
Duration: Long-term
Responsibilities:
- 8+ years of hands-on experience in Application Security and Penetration Testing across Web, APIs, Mobile, Thick Client, and Network environments.
- Performed comprehensive Web Application, Web Services (API), Mobile Application, Network, and Thick Client Penetration Testing using industry-standard methodologies (OWASP, PTES, NIST).
- Expert in using Burp Suite Professional for manual security testing, vulnerability validation, and exploitation.
- Conducted manual penetration testing to identify, validate, and exploit security vulnerabilities while eliminating false positives.
- Performed secure code assessments and vulnerability analysis to identify application security weaknesses and recommend remediation.
- Strong understanding of CVSS v3/v4 scoring for vulnerability prioritization and risk assessment.
- Assisted in technical scoping and planning of security assessment engagements based on business and application risk.
- Provided clear, actionable penetration test reports with technical findings, business impact, proof of concept, and remediation guidance.
- Collaborated with development and infrastructure teams to validate fixes through retesting and remediation verification .
- Hands-on experience with SAST, SCA , and vulnerability management platforms to support secure SDLC initiatives.
- Developed and enhanced Python-based automation scripts to improve security testing efficiency and repetitive assessment tasks.
- Experience assessing security risks in applications utilizing Large Language Models (LLMs) , including prompt injection, insecure output handling, and data leakage scenarios.
- Performed false positive analysis and vulnerability triage across multiple security scanning tools.
- Supported network infrastructure security assessments , including internal and external penetration testing.
- Identified and validated OWASP Top 10 vulnerabilities such as SQL Injection, XSS, SSRF, XXE, CSRF, IDOR, Authentication, and Authorization flaws.
- Worked with secure authentication mechanisms including OAuth 2.0, OpenID Connect (OIDC), JWT, and SAML during application security assessments.
- Escalated critical vulnerabilities and high-risk findings to stakeholders and Regional Operations Managers for timely remediation.
- Contributed to continuous improvement of vulnerability management processes, security testing methodologies, and scanning configurations.
- Reviewed security test cases and maintained security assessment documentation to align with organizational standards.
- Excellent communication skills with experience presenting technical findings to developers, architects, and executive stakeholders.
- Preferred certifications: OSCP, CISSP, CPT, CEPT, CMWAPT .
Primary Skills - - Application Security
- Penetration Testing
- Web Application Security
- API Security Testing
- Mobile Application Security
- Thick Client Security Testing
- Network Penetration Testing
- Burp Suite Professional
- Python Scripting
- OWASP Top 10
- CVSS Scoring
- SAST
- SCA
- Secure Code Review
- Vulnerability Assessment
- Vulnerability Management
- LLM Security Testing
- Secure SDLC
- Risk Assessment
- Report Writing & Client Consultation
NJTECH is a globally managed IT service, IT consulting and Business solutions partner. Our "High Performance Business" strategy builds our expertise in technology and consulting. Our offshore consulting plays a major role in helping clients to achieve their objectives in the highest level; ultimately creating sustainable value to customers. Come, transform your career with us and be a part of our high-performing team.
Regards,
Aaran D
first seen 2026-08-10 08:40:01 · last verified 2026-08-24 01:30:01
pentestcareers.com // breach the job market