Principal Ethical Hacker / Penetration Tester

SoftPathTechnologies·Albany, New York·Posted 9d ago·via Talent.com

RegionUSA
Apply Now

Job description

Job Title: Principal Ethical Hacker / Penetration Tester

Client: Deloitte

Employment Type: W2 Contract

Location: Albany, NY Hybrid

Travel: Required to travel to Albany, NY twice per month

Job Summary

Deloitte is seeking a highly skilled Principal Ethical Hacker / Penetration Tester with strong expertise in Java application security, penetration testing, secure coding, and DevSecOps . The ideal candidate will identify, exploit, assess, and help remediate vulnerabilities in enterprise-scale Java applications and infrastructure.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field
  • 6+ years of software development and/or security experience
  • Strong Core Java programming experience
  • Experience with penetration testing and ethical hacking
  • Experience securing large-scale enterprise Java applications
  • Strong knowledge of application security and OWASP
  • Experience identifying SQL Injection, XSS, authentication, authorization, and other web vulnerabilities
  • Hands-on experience with Burp Suite and Metasploit
  • Experience with SAST/DAST tools, preferably Fortify on Demand
  • Strong understanding of cryptography and SSL/TLS
  • Experience with secure code review
  • Scripting experience with Python and/or Bash

Key Responsibilities

  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure
  • Identify security vulnerabilities through automated and manual testing
  • Develop and use custom exploits to simulate attacker techniques
  • Perform secure code reviews of Java applications
  • Collaborate with development teams to identify security weaknesses early in the SDLC
  • Work with testing teams to integrate security testing with manual and automated testing
  • Provide secure coding guidance and remediation recommendations
  • Monitor emerging Java security threats and vulnerabilities
  • Review published CVEs and NIST security advisories
  • Assess URLs, query parameters, browser tokens, cache mechanisms, and application data for attack vectors
  • Evaluate production and non-production architectures
  • Document security findings, risk assessments, and recommended remediation
  • Communicate findings to technical and non-technical stakeholders
  • Contribute to secure development policies and processes

Preferred Qualifications

  • OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or similar certification
  • Java secure code review experience
  • API security testing
  • Cloud security testing
  • Mobile application penetration testing
  • HIPAA/security compliance knowledge
  • Familiarity with MITRE ATT&CK Framework

first seen 2026-09-30 01:30:01 · last verified 2026-10-08 01:30:01


pentestcareers.com // breach the job market

Principal Ethical Hacker / Penetration Tester at SoftPathTechnologies | Pentest Careers