Security Consultant – Penetration Testing, DevSecOps
RegionUSA
Job description
Job Description: - Perform manual and automated penetration testing of web applications, APIs, mobile applications, cloud environments, and supporting infrastructure
- Conduct reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities using OWASP, PTES, NIST, and MITRE ATT&CK methodologies
- Identify vulnerabilities, validate exploitability, assess business risk, and provide actionable remediation recommendations
- Execute security assessments of microservices, containers, Kubernetes, and cloud-native applications
- Develop proof-of-concepts demonstrating security weaknesses and attack paths
- Prepare detailed technical reports and executive summaries for customers and stakeholders
- Integrate security controls and testing into CI/CD pipelines
- Implement and manage SAST, DAST, SCA, IaC, Container Security, Secrets Detection, and API Security testing solutions
- Collaborate with development teams to remediate vulnerabilities and adopt secure coding practices
- Participate in security architecture reviews, threat modeling exercises, and secure design assessments
- Automate security testing and compliance validation within DevOps toolchains
- Develop security guardrails and policy-as-code capabilities
- Perform vulnerability triage, risk prioritization, and remediation tracking
- Support continuous security monitoring and risk assessment activities
- Analyze emerging threats, attack techniques, and security trends
- Assist in developing security standards, procedures, and best practices
- Work with engineering, cloud, and infrastructure teams to enhance organizational security posture
- Present findings and recommendations to developers, architects, engineering teams, and leadership
- Provide security consulting throughout the software development lifecycle
Requirements: - Bachelor's degree in Computer Science, Information Security, Engineering, or a related field
- 5-8 years of hands-on cybersecurity experience
- Minimum 3+ years of experience conducting application and API penetration testing
- Experience implementing or supporting DevSecOps initiatives within CI/CD environments
- Strong understanding of Web Application Security, API Security, Secure SDLC, OWASP Top 10, OWASP API Top 10, MITRE ATT&CK, Threat Modeling, and Vulnerability Management
- Hands-on experience with Burp Suite Professional, Nmap, Nessus / Qualys / Tenable, Metasploit, Kali Linux, Checkmarx, Veracode, Snyk, SonarQube, and GitHub Actions / Azure DevOps / Jenkins
- One or more listed security certifications: OSCP, CRTO, PNPT, CEH, GWAPT, GPEN, CISSP, CCSP, Azure Security Engineer Associate, or AWS Security Specialty
- Experience with container security (Docker, Kubernetes)
- Experience conducting cloud penetration testing
- Understanding of Infrastructure as Code (Terraform, CloudFormation)
- Familiarity with Red Team methodologies and adversary simulation
- Exposure to Zero Trust Architecture and Secure-by-Design principles
- Experience with AI/LLM security testing is a plus
- Excellent communication, consulting, and stakeholder management skills
Benefits: - Vacation: 12-25 days, depending on grade
- Company paid holidays
- Personal Days
- Sick Leave
- Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)
- Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)
- Life and disability insurance
- Employee assistance programs
- Other benefits as provided by local policy and eligibility
- Variable incentives, bonuses, or commissions may be available
first seen 2026-09-16 21:30:01 · last verified 2026-09-16 21:30:01
pentestcareers.com // breach the job market