Senior Penetration Tester
RegionUSA
Job description
Responsibilities
- Lead penetration tests on web applications and underlying infrastructure for vulnerabilities using both manual and automated techniques.
- Develop test plans that validate identified vulnerabilities and demonstrate exploitability to engineering teams, security peers, and senior leadership.
- Collaborate with detection engineering and incident response on purple team exercises, validating that preventative and detective controls behave as expected against realistic adversary techniques.
- Grow the team's pentesting capabilities in infrastructure and cloud-native domains, including CI/CD pipelines, Active Directory, AWS, and Kubernetes.
- Recommend remediations that address root causes, including code changes, architectural improvements, and control adjustments.
- Stay current with attacker tradecraft. Share knowledge with the broader security team and mentor engineers on offensive techniques and how to think like an attacker.
Basic Qualifications
- Bachelor's Degree required from an accredited, not for profit, in person university or college (preferably in Computer Science, Cybersecurity, or related field).
- A track record of commitment to prior employers.
- 6 years of total experience in a technical role such as security, software development, or systems engineering, with at least 3 years focused on penetration testing or offensive security.
- Demonstrated experience with web application and API penetration testing, including identifying and exploiting attack chains across complex application logic, authentication, and authorization flows.
- Experience writing reports that clearly demonstrate vulnerability risk, business impact, and remediation paths to developers and senior leadership.
- Ability to perform secure code review and identify vulnerabilities in source code, including authentication, authorization, injection, and business logic flaws.
- Scripting and programming proficiency in Python, PowerShell, or similar, with the ability to read and understand application code in languages like C#, Java, JavaScript, or Go.
- Understanding of defense-in-depth principles and ability to recommend layered mitigations beyond fixing individual findings.
- Security certifications such as OSCP, OSWE, OSEP, GPEN, GXPN, or similar.
Preferred Qualifications and Skills
- In-depth experience with offensive security tools such as Burp Suite, OWASP ZAP, Nmap, Bloodhound, and Metasploit.
- Familiarity with Active Directory exploitation tools and techniques.
- Familiarity with C2 frameworks such as Cobalt Strike, Sliver, or Mythic.
- Experience planning and executing red team and purple team scenarios.
- Experience with adversary emulation methodologies and frameworks (MITRE ATT&CK).
- Experience testing modern applications in cloud-native tech stacks.
- Experience with mobile application penetration testing.
- Familiarity with AI and LLM security testing, including prompt injection, indirect prompt injection, agentic system risks, and MCP server assessment.
- Hands-on experience implementing security tools into CI/CD pipelines.
- Working knowledge of network, system, and database administration concepts as they relate to attack surface analysis.
- Strong communication skills with both technical teams and senior leadership, particularly translating technical exploits into business risk.
- Experience coordinating with application teams to drive security by design principles.
- Ability to mentor and train team members on offensive techniques and risk prioritization.
- A self-starter who follows ideas through to completion and drives offensive security work forward independently.
What’s in it for You
When you join CoStar Group, you’ll experience a collaborative and innovative culture working alongside the best and brightest to empower our people and customers to succeed.
We offer you generous compensation and performance-based incentives. CoStar Group also invests in your professional and academic growth with internal training, and tuition reimbursement.
Our benefits package includes (but is not limited to):
- Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
- Life, legal, and supplementary insurance
- Virtual and in person mental health counseling services for individuals and family
- Commuter and parking benefits
- 401(K) retirement plan with matching contributions
- Employee stock purchase plan
- Paid time off
- Tuition reimbursement
- On-site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes
- Access to CoStar Group’s Employee Resource Groups
- Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks
first seen 2026-08-10 12:48:01 · last verified 2026-08-10 12:48:01
pentestcareers.com // breach the job market