Web Application Penetration Tester
BLACK HILLS INFORMATION SECURITY INC
United States
about 1 month ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$120,000.0 - $150,000.0
Working hours
Regular working hours
Job source
Tech stack
JavaScript (Programming Language)
Private Networks
Application Programming Interfaces (APIs)
Artificial Intelligence
Business Logic
Software System Penetration Testing
Bash Shell
Burp Suite
Encodings
Cross-Origin Resource Sharing (Ajax Programming)
Programming Tools
Mobile Application Software
+14 more
Python (Programming Language)
Nmap
Open Web Application Security
Red Team (Cyber Security)
Software Engineering
Web Applications
Web Application Frameworks
WebSocket
Rust (Programming Language)
Scripting
Cross-Site Scripting (XSS)
GWAPT
Information Technology
Web Api
Job description
We’re looking for an experienced Webapp Penetration Tester to perform penetration tests against modern web applications and web APIs, as well as security assessments of all kinds. The ideal candidate combines a strong foundation in information technology or software development with hands-on experience identifying, exploiting, and communicating web-specific security risks.What You’ll Do
- Perform penetration tests against live web applications and web APIs, with and without source code
- Follow a repeatable process that ensures thorough discovery, coverage, and documentation of the attack surface
- Recognize in HTTP traffic the presence and use of web application frameworks, technologies, and third-party services on both the client side and the server side.
- Identify and exploit coding errors, misconfigurations, business logic flaws, privilege separation gaps, account recovery flaws, and weaknesses in infrastructure software and third-party components and services.
- Perform attack path analysis and vulnerability chaining to illustrate the true, realistic impact of findings.
- Conduct traditional penetration testing in two or more other areas: mobile applications, external/internal network testing, cloud platforms and services, social engineering, C2 and post-exploitation activities.
- Write clear, accurate, and actionable reports with technical details, risk ratings, evidence, and remediation guidance, without relying on AI writing tools.
- Present findings to technical teams and executive stakeholders
- Stay current with emerging attack techniques, offensive tooling, and the evolution of common webapp components, frameworks, and infrastructure software
Requirements
- 5 years hands-on experience performing application-level penetration tests, red team assessments, or offensive security testing
- Strong understanding of penetration testing methodologies: reconnaissance, enumeration, exploitation, privilege escalation, lateral movement, persistence, and reporting
- Familiarity with the OWASP Top Ten (for web, for API, for mobile) and ability to explain the causes and solutions for each item
- Understanding of application- and browser-level security concepts: authentication and authorization, privilege separation, CORS, data encoding schemes, WebSockets, HTTP, DOM storage, Same Origin Policy, JWTs, etc.
- Ability to explain security implications and common errors in those areas that contribute to risk
- Familiarity with offensive tools: Burp Suite, Caido, Nmap, browser-based developer tools, Nuclei, AI-augmented research and analysis
- Experience with JavaScript and another scripting language (Python, Rust, Bash, etc)
- Strong written and verbal communication skills without reliance on AI-generated language.
- Ability to work independently and manage assessment timelines
Preferred Qualifications
- Experience developing or QA testing web applications, web APIs, or mobile applications
- Experience developing custom tooling or automation in JavaScript and another scripting language
- Relevant certifications: OSWE, GWAPT, GXPN, Burp Certified Practitioner, etc
- Experience writing technical blog posts, presenting research, contributing to tools, or developing security training content
You’ll Thrive Here If You
- Can independently assess an unfamiliar web application, identify realistic attack paths, and illustrate the risks they pose
- Can clearly explain root causes for security issues, grounded in real-world experience
- Find satisfaction in writing reports that are technically accurate, easy to understand, and useful to defenders
- Know when to automate and when to take a methodical manual approach, * Are you willing to complete a background check?
- How many years experience do you have with penetration testing?
- How many years experience do you have with Web application penetration testing?
- In two sentences, what is the difference between XSS and Cross Site Request Forgery?
Benefits & conditions
$120,000 - $150,000 a year - Full-time, Pulled from the full job description
- Parental leave
- 401(k)
- Health insurance
- Retirement plan
- Paid time off
- Vision insurance
- Dental insurance, * 401(k)
- Dental insurance
- Employee assistance program
- Health insurance
- Paid time off
- Parental leave
- Retirement plan
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
over 1 year ago
LM
Luis Minvielle
The 8 Best Code Testing Tools
over 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
TL
Thomas Limbüchler
Should senior developers refuse interview coding challenges?
over 5 years ago
DC
Daniel Cranney
The Overflow: Security and Privacy
5 months ago