Web Application Penetration Testing
Overview
In this role you will perform comprehensive web application security testing for government-related systems, applying attacker-minded methodologies to uncover vulnerabilities. You will work with security engineers and client teams to validate fixes and drive secure configurations, delivering technical and executive-level findings aligned with SEC530. The position emphasizes practical risk demonstration through proofs-of-concept and collaboration across stakeholders. You will shape security posture by translating findings into actionable remediation in a cross-functional, client-facing environment.
ResponsibilitiesConduct web application, API, and network penetration tests to identify vulnerabilitiesPerform grey-box and black-box testing per NIST SP 800-115 and OWASP Testing FrameworkEvaluate authentication, session management, access controls, and data handling for security flawsExecute vulnerability exploitation and proof-of-concept validationDocument findings with remediation recommendations for stakeholdersCollaborate with internal security engineers and client teams to verify fixes and retestPrepare technical and executive reports aligning with SEC530Support secure configuration reviews and federal/state cybersecurity compliance
Key requirementsBachelor’s degree in computer science, Cybersecurity, Information Technology, or related field (or equivalent experience)7 years of experience in penetration testing or ethical hacking with focus on web apps and APIsIn-depth knowledge of web technologies, networking protocols, authentication systems, and encryption standardsStrong understanding of secure development practices (SDLC) and OWASP Top 10Excellent analytical, documentation, and communication skillsCEH – RequiredOSCP – PreferredCompTIA Security / CySA / GPEN / GWAPT – DesirableCritical thinkerDetail-orientedProactiveWeb technologiesNetworking protocolsAuthentication systems