Web Application Penetration Tester

BLACK HILLS INFORMATION SECURITY INC
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$120,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Private Networks Application Programming Interfaces (APIs) Artificial Intelligence Business Logic Software System Penetration Testing Bash Shell Burp Suite Encodings Cross-Origin Resource Sharing (Ajax Programming) Programming Tools Mobile Application Software
+14 more
Python (Programming Language) Nmap Open Web Application Security Red Team (Cyber Security) Software Engineering Web Applications Web Application Frameworks WebSocket Rust (Programming Language) Scripting Cross-Site Scripting (XSS) GWAPT Information Technology Web Api

Job description

We’re looking for an experienced Webapp Penetration Tester to perform penetration tests against modern web applications and web APIs, as well as security assessments of all kinds. The ideal candidate combines a strong foundation in information technology or software development with hands-on experience identifying, exploiting, and communicating web-specific security risks.What You’ll Do

  • Perform penetration tests against live web applications and web APIs, with and without source code
  • Follow a repeatable process that ensures thorough discovery, coverage, and documentation of the attack surface
  • Recognize in HTTP traffic the presence and use of web application frameworks, technologies, and third-party services on both the client side and the server side.
  • Identify and exploit coding errors, misconfigurations, business logic flaws, privilege separation gaps, account recovery flaws, and weaknesses in infrastructure software and third-party components and services.
  • Perform attack path analysis and vulnerability chaining to illustrate the true, realistic impact of findings.
  • Conduct traditional penetration testing in two or more other areas: mobile applications, external/internal network testing, cloud platforms and services, social engineering, C2 and post-exploitation activities.
  • Write clear, accurate, and actionable reports with technical details, risk ratings, evidence, and remediation guidance, without relying on AI writing tools.
  • Present findings to technical teams and executive stakeholders
  • Stay current with emerging attack techniques, offensive tooling, and the evolution of common webapp components, frameworks, and infrastructure software

Requirements

  • 5 years hands-on experience performing application-level penetration tests, red team assessments, or offensive security testing
  • Strong understanding of penetration testing methodologies: reconnaissance, enumeration, exploitation, privilege escalation, lateral movement, persistence, and reporting
  • Familiarity with the OWASP Top Ten (for web, for API, for mobile) and ability to explain the causes and solutions for each item
  • Understanding of application- and browser-level security concepts: authentication and authorization, privilege separation, CORS, data encoding schemes, WebSockets, HTTP, DOM storage, Same Origin Policy, JWTs, etc.
  • Ability to explain security implications and common errors in those areas that contribute to risk
  • Familiarity with offensive tools: Burp Suite, Caido, Nmap, browser-based developer tools, Nuclei, AI-augmented research and analysis
  • Experience with JavaScript and another scripting language (Python, Rust, Bash, etc)
  • Strong written and verbal communication skills without reliance on AI-generated language.
  • Ability to work independently and manage assessment timelines

Preferred Qualifications

  • Experience developing or QA testing web applications, web APIs, or mobile applications
  • Experience developing custom tooling or automation in JavaScript and another scripting language
  • Relevant certifications: OSWE, GWAPT, GXPN, Burp Certified Practitioner, etc
  • Experience writing technical blog posts, presenting research, contributing to tools, or developing security training content

You’ll Thrive Here If You

  • Can independently assess an unfamiliar web application, identify realistic attack paths, and illustrate the risks they pose
  • Can clearly explain root causes for security issues, grounded in real-world experience
  • Find satisfaction in writing reports that are technically accurate, easy to understand, and useful to defenders
  • Know when to automate and when to take a methodical manual approach, * Are you willing to complete a background check?
  • How many years experience do you have with penetration testing?
  • How many years experience do you have with Web application penetration testing?
  • In two sentences, what is the difference between XSS and Cross Site Request Forgery?

Benefits & conditions

$120,000 - $150,000 a year - Full-time, Pulled from the full job description

  • Parental leave
  • 401(k)
  • Health insurance
  • Retirement plan
  • Paid time off
  • Vision insurance
  • Dental insurance, * 401(k)
  • Dental insurance
  • Employee assistance program
  • Health insurance
  • Paid time off
  • Parental leave
  • Retirement plan
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

9:56 min

Expanding browser capabilities with modern web APIs

Ire Aderinokun · JS Congress

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

7:44 min

Bootstrapping a test-driven asp.net web api

Alex Banul · LIVE

47 sec

Cross-engine support for the Web Serial API

Christian Liebel Christian Liebel · WWC Europe 2026

Videos

See all

Related articles

See all