Web Application Security Test Engineer

Sensiple Inc.
Addison, TX, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$135,200.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Biometrics Burp Suite Static Program Analysis Multi-Factor Authentication Fiddler (Software) Identity and Access Management Open Web Application Security Public Key Infrastructure Web Application Security Web Applications Enterprise Software Applications
+4 more
Software Security Information Technology Static Application Security Testing Dynamic Application Security Testing

Requirements

This is a Web Application Security Testing role, not a penetration testing position. The focus is on candidates who have hands-on experience testing real enterprise-level web applications (such as banking platforms or other large-scale applications), rather than performing generic or exploratory penetration testing. The ideal candidate must have a deep understanding of OWASP Top 10 vulnerabilities, including the ability to clearly explain the root cause of each vulnerability, how to test for it, and how to fix it., * Strong knowledge of SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) is the key on this role, along with hands-on experience using tools like Burp Suite and similar security testing platforms.

  • A key requirement of the role is strong expertise in authentication and authorization testing, including areas such as login systems, password-based authentication, multi-factor authentication (MFA/OTP), biometrics, and understanding potential failure points within these flows.
  • Beyond identifying vulnerabilities, the candidate must act as a security advisor to development teams. This means not only detecting issues but also being able to explain the root cause, recommend solutions, and guide developers on how to remediate them effectively.
  • Deep understanding of different web application technologies, web protocols (HTTP, HTTPS, etc.), browser technologies, etc.
  • In depth domain understanding of application security in terms of Identity and Access Management (IAM), different authentication technologies (passwords, biometrics, OTP, digital certificates & PKI, device authentication, FIDO U2F/Passkeys, etc.
  • Proven expertise on different security testing tools (Proxy tools like Fiddler, Black box security testing tools like Burp, Static Security Code analysis tools.
  • Deep understanding of different application security vulnerabilities such as OWASP Top 10, SANS Top 25, CWE, attack patterns (CAPEC), etc.
  • Bachelor’s Degree in Computer Science or equivalent experience.
  • Must be self-directed, able to work independently, as well as work in a team-oriented and fast paced environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

6:13 min

Analyzing test coverage gaps in standard web applications

Jorge Gonzalez Pliego Jorge Gonzalez Pliego · Europe 2026 Virtual

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:41 min

Exploring possession and biometric authentication factors

Clemens Hübner Clemens Hübner · WWC 2023

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

Videos

See all

Related articles

See all