> Markdown version of [/jobs/ext/1336131-senior-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1336131-senior-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Penetration Tester - **Company:** Pluto, Inc. - **Location:** Newark, NJ, United States - **Experience:** Expert - **Salary:** $112,768.0 - $135,806.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Private Networks, Microsoft Windows, Active Directory, Amazon Web Services, Business Logic, Software System Penetration Testing, Microsoft Azure, Bash Shell, Burp Suite, Mobile Application Development, Cloud Computing Security, Code Review, Continuous Integration, Linux, Mobile Application Software, Python (Programming Language), Kali Linux, Wireless Security, Nmap, Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Phishing, Red Team (Cyber Security), Web Application Security, Session Management, Wireshark, Google Cloud, Postman, Software Security, Git, Metasploit, Nessus, Windows Security, Devsecops, Docker, Vulnerability Analysis - **Published:** July 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=03486fad9881e9e5 ## About the Role * Strong understanding of Web Application Security * Experience performing Manual Penetration Testing * Knowledge of OWASP Top 10 * Understanding of OWASP API Security Top 10 * Experience with Network Penetration Testing * Cloud Security knowledge (AWS, Azure, or GCP) * Linux and Windows security knowledge * Active Directory security testing * Experience identifying and validating vulnerabilities * Excellent technical documentation and report writing skills * Strong communication skills * Ability to work independently and collaboratively Preferred Experience Experience with one or more of the following: * Burp Suite Professional * Nmap * Metasploit Framework * Nessus * Wireshark * Kali Linux * ffuf * Nuclei * Postman * SQLMap * BloodHound * CrackMapExec * Responder * Impacket * Docker * Git * Python * PowerShell * Bash Preferred Certifications One or more of the following certifications is an advantage: * OSCP * PNPT * CEH * GPEN * CPTS * CISSP * Security+ * eCPPT * CRTO * CRTP Nice to Have * Source Code Review experience * Red Team experience * Social Engineering engagements * Phishing assessments * Azure and Microsoft 365 security * Kubernetes security * Container security * CI/CD security * DevSecOps experience * Threat Modeling * Secure SDLC knowledge ## Description * Perform Web Application Penetration Testing * Conduct API Security Testing * Perform External Network Penetration Testing * Conduct Internal Network Penetration Testing * Execute Cloud Security Assessments (AWS, Azure, Google Cloud) * Perform Mobile Application Penetration Testing (iOS & Android) * Conduct Wireless Security Assessments * Identify, validate, and exploit security vulnerabilities safely * Perform manual penetration testing beyond automated vulnerability scanning * Test authentication, authorization, session management, and business logic flaws * Assess Active Directory security and privilege escalation opportunities * Review application security architecture * Create detailed technical and executive penetration testing reports * Provide remediation recommendations aligned with industry best practices * Participate in client meetings to explain findings and remediation strategies * Support security validation after remediation (retesting) * Stay current with emerging vulnerabilities, exploits, attack techniques, and security research ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)