Penetration Tester - Offensive Security / Application
We are in the process of building a new offensive security team focused on application security that will be working on a mission critical project for a Fortune 500 client. For this we are looking to build an expert squad of 3x application penetration testers that will form the core of the team.
This is an extensive, multi-year program that will create a comprehensive security assessment of web & mobile applications on a cloud-native environment. Will be performing Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) and will have direct access to the source code of a household name brand.
Those applying should have extensive experience in conducting comprehensive penetration testing on web and mobile applications to identify vulnerabilities, be experienced in developing security testing methodologies and conducting offensive security operations to simulate real-world attacks.
- 3-5 years of experience in application security testing and source code review.
- Professional certifications such as GWAPT (GIAC Web Application Penetration Tester), OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), or similar.
- Proficiency in multiple programming languages and understanding of secure coding practices.
- Experience with tools like Burp Suite Pro, Checkmarx, Corellium, Synopsys, Acunetix, VeraCode, SAST & DAST Tools, Plextrac, Cloud security (AWS / Azure / Oracle), Postman, SmartBear ReadyAPI, SoapUI, and Hashicorp Vault
This is an amazing opportunity to be a member of a new team formation that will play a pivotal role in securing the operations of a leading organization. Please reach out to brett.marsh@xcede.com to find out more