> Markdown version of [/jobs/ext/1173473-web-application-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1173473-web-application-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Web Application Penetration Tester - **Company:** BLACK HILLS INFORMATION SECURITY INC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $120,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Private Networks, Application Programming Interfaces (APIs), Artificial Intelligence, Business Logic, Software System Penetration Testing, Bash Shell, Burp Suite, Encodings, Cross-Origin Resource Sharing (Ajax Programming), Programming Tools, Mobile Application Software, Python (Programming Language), Nmap, Open Web Application Security, Red Team (Cyber Security), Software Engineering, Web Applications, Web Application Frameworks, WebSocket, Rust (Programming Language), Scripting, Cross-Site Scripting (XSS), GWAPT, Information Technology, Web Api - **Published:** July 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d0abd73e9356efb9 ## About the Role * 5 years hands-on experience performing application-level penetration tests, red team assessments, or offensive security testing * Strong understanding of penetration testing methodologies: reconnaissance, enumeration, exploitation, privilege escalation, lateral movement, persistence, and reporting * Familiarity with the OWASP Top Ten (for web, for API, for mobile) and ability to explain the causes and solutions for each item * Understanding of application- and browser-level security concepts: authentication and authorization, privilege separation, CORS, data encoding schemes, WebSockets, HTTP, DOM storage, Same Origin Policy, JWTs, etc. * Ability to explain security implications and common errors in those areas that contribute to risk * Familiarity with offensive tools: Burp Suite, Caido, Nmap, browser-based developer tools, Nuclei, AI-augmented research and analysis * Experience with JavaScript and another scripting language (Python, Rust, Bash, etc) * Strong written and verbal communication skills without reliance on AI-generated language. * Ability to work independently and manage assessment timelines Preferred Qualifications * Experience developing or QA testing web applications, web APIs, or mobile applications * Experience developing custom tooling or automation in JavaScript and another scripting language * Relevant certifications: OSWE, GWAPT, GXPN, Burp Certified Practitioner, etc * Experience writing technical blog posts, presenting research, contributing to tools, or developing security training content You'll Thrive Here If You * Can independently assess an unfamiliar web application, identify realistic attack paths, and illustrate the risks they pose * Can clearly explain root causes for security issues, grounded in real-world experience * Find satisfaction in writing reports that are technically accurate, easy to understand, and useful to defenders * Know when to automate and when to take a methodical manual approach, * Are you willing to complete a background check? * How many years experience do you have with penetration testing? * How many years experience do you have with Web application penetration testing? * In two sentences, what is the difference between XSS and Cross Site Request Forgery? ## Description We're looking for an experienced Webapp Penetration Tester to perform penetration tests against modern web applications and web APIs, as well as security assessments of all kinds. The ideal candidate combines a strong foundation in information technology or software development with hands-on experience identifying, exploiting, and communicating web-specific security risks.What You'll Do * Perform penetration tests against live web applications and web APIs, with and without source code * Follow a repeatable process that ensures thorough discovery, coverage, and documentation of the attack surface * Recognize in HTTP traffic the presence and use of web application frameworks, technologies, and third-party services on both the client side and the server side. * Identify and exploit coding errors, misconfigurations, business logic flaws, privilege separation gaps, account recovery flaws, and weaknesses in infrastructure software and third-party components and services. * Perform attack path analysis and vulnerability chaining to illustrate the true, realistic impact of findings. * Conduct traditional penetration testing in two or more other areas: mobile applications, external/internal network testing, cloud platforms and services, social engineering, C2 and post-exploitation activities. * Write clear, accurate, and actionable reports with technical details, risk ratings, evidence, and remediation guidance, without relying on AI writing tools. * Present findings to technical teams and executive stakeholders * Stay current with emerging attack techniques, offensive tooling, and the evolution of common webapp components, frameworks, and infrastructure software ## Related Videos - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Project Fugu: Extending the web](https://www.wearedevelopers.com/videos/832-project-fugu-extending-the-web) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Prototyping with Hardware and the Web](https://www.wearedevelopers.com/videos/651-prototyping-with-hardware-and-the-web) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)