> Markdown version of [/jobs/ext/1215690-web-application-security-test-engineer](https://www.wearedevelopers.com/jobs/ext/1215690-web-application-security-test-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Web Application Security Test Engineer - **Company:** Sensiple Inc. - **Location:** Addison, TX, United States - **Salary:** $135,200.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Biometrics, Burp Suite, Static Program Analysis, Multi-Factor Authentication, Fiddler (Software), Identity and Access Management, Open Web Application Security, Public Key Infrastructure, Web Application Security, Web Applications, Enterprise Software Applications, Software Security, Information Technology, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cedbc8634411bc3a ## About the Role This is a Web Application Security Testing role, not a penetration testing position. The focus is on candidates who have hands-on experience testing real enterprise-level web applications (such as banking platforms or other large-scale applications), rather than performing generic or exploratory penetration testing. The ideal candidate must have a deep understanding of OWASP Top 10 vulnerabilities, including the ability to clearly explain the root cause of each vulnerability, how to test for it, and how to fix it., * Strong knowledge of SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) is the key on this role, along with hands-on experience using tools like Burp Suite and similar security testing platforms. * A key requirement of the role is strong expertise in authentication and authorization testing, including areas such as login systems, password-based authentication, multi-factor authentication (MFA/OTP), biometrics, and understanding potential failure points within these flows. * Beyond identifying vulnerabilities, the candidate must act as a security advisor to development teams. This means not only detecting issues but also being able to explain the root cause, recommend solutions, and guide developers on how to remediate them effectively. * Deep understanding of different web application technologies, web protocols (HTTP, HTTPS, etc.), browser technologies, etc. * In depth domain understanding of application security in terms of Identity and Access Management (IAM), different authentication technologies (passwords, biometrics, OTP, digital certificates & PKI, device authentication, FIDO U2F/Passkeys, etc. * Proven expertise on different security testing tools (Proxy tools like Fiddler, Black box security testing tools like Burp, Static Security Code analysis tools. * Deep understanding of different application security vulnerabilities such as OWASP Top 10, SANS Top 25, CWE, attack patterns (CAPEC), etc. * Bachelor's Degree in Computer Science or equivalent experience. * Must be self-directed, able to work independently, as well as work in a team-oriented and fast paced environment. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) - [Biometric Phone Chargers, $40m Domain Names & AI Movies Winning Awards - Peter Kröner](https://www.wearedevelopers.com/videos/1810-biometric-phone-chargers-40m-domain-names-ai-movies-winning-awards-peter-kroner) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [11 Best Practices For PHP Security](https://www.wearedevelopers.com/magazine/90-11-best-practices-for-php-security)