Principal Ethical Hacker / Penetration Tester
RegionUSA
Job description
Job Title: Principal Ethical Hacker / Penetration Tester
Client: Deloitte
Employment Type: W2 Contract
Location: Albany, NY Hybrid
Travel: Required to travel to Albany, NY twice per month
Job Summary
Deloitte is seeking a highly skilled Principal Ethical Hacker / Penetration Tester with strong expertise in Java application security, penetration testing, secure coding, and DevSecOps . The ideal candidate will identify, exploit, assess, and help remediate vulnerabilities in enterprise-scale Java applications and infrastructure.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, or related field
- 6+ years of software development and/or security experience
- Strong Core Java programming experience
- Experience with penetration testing and ethical hacking
- Experience securing large-scale enterprise Java applications
- Strong knowledge of application security and OWASP
- Experience identifying SQL Injection, XSS, authentication, authorization, and other web vulnerabilities
- Hands-on experience with Burp Suite and Metasploit
- Experience with SAST/DAST tools, preferably Fortify on Demand
- Strong understanding of cryptography and SSL/TLS
- Experience with secure code review
- Scripting experience with Python and/or Bash
Key Responsibilities
- Conduct penetration tests and vulnerability assessments for Java applications and infrastructure
- Identify security vulnerabilities through automated and manual testing
- Develop and use custom exploits to simulate attacker techniques
- Perform secure code reviews of Java applications
- Collaborate with development teams to identify security weaknesses early in the SDLC
- Work with testing teams to integrate security testing with manual and automated testing
- Provide secure coding guidance and remediation recommendations
- Monitor emerging Java security threats and vulnerabilities
- Review published CVEs and NIST security advisories
- Assess URLs, query parameters, browser tokens, cache mechanisms, and application data for attack vectors
- Evaluate production and non-production architectures
- Document security findings, risk assessments, and recommended remediation
- Communicate findings to technical and non-technical stakeholders
- Contribute to secure development policies and processes
Preferred Qualifications
- OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or similar certification
- Java secure code review experience
- API security testing
- Cloud security testing
- Mobile application penetration testing
- HIPAA/security compliance knowledge
- Familiarity with MITRE ATT&CK Framework
first seen 2026-09-30 01:30:01 · last verified 2026-10-08 01:30:01
pentestcareers.com // breach the job market