Sr. Web App Penetration Tester

SixGen, Inc
United States
21 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$125,000.0 - $145,000.0
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) Software System Penetration Testing Automation of Tests Cyber Security Databases Mobile Application Software Web Application Security Web Applications Scripting Cloud Platform System Cyber Warfare
+1 more
Vulnerability Analysis

Job description

This role goes far beyond automated scanning. Successful candidates will conduct in-depth assessments of web applications, APIs, mobile applications, and supporting infrastructure while leveraging custom tooling, manual testing techniques, and advanced exploitation methodologies to uncover impactful security findings., Web Application Security Assessments Conduct penetration testing of web applications, APIs, mobile applications, databases, and client-side technologies. Perform application enumeration, endpoint discovery, vulnerability research, and exploitation activities. Identify, validate, and assess vulnerabilities across complex environments. Analyze attack paths and security weaknesses to determine business and operational impact. Technical Analysis & Research Develop and utilize custom tools, scripts, and payloads to support testing activities. Perform network mapping, vulnerability analysis, and security assessments across applications and supporting infrastructure. Research emerging vulnerabilities, attack techniques, and exploitation methodologies. Support post-exploitation activities involving cloud and enterprise environments when applicable. Client Engagement & Reporting Collaborate with clients and internal teams to define scope, review findings, and recommend remediation strategies. Communicate technical concepts and findings to both technical and non-technical stakeholders. Produce comprehensive reports, including detailed findings, exploitation procedures, risk analysis, and mitigation recommendations. Participate in client meetings and provide ongoing updates throughout assessment activities.

Requirements

We are seeking a skilled and motivated Senior Web Application Penetration Tester to join our growing cyber operations team. The ideal candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques, with the ability to identify complex attack paths and develop creative solutions to challenging security problems., 5+ years of experience in web application penetration testing or offensive cybersecurity. Demonstrated experience conducting manual web application security assessments. Knowledge of modern web application vulnerabilities, attack methodologies, and exploitation techniques. Experience with network mapping, vulnerability scanning, and penetration testing methodologies. Familiarity with NIST 800-series standards and cybersecurity best practices. Experience developing scripts, payloads, or custom testing tools. Strong analytical, problem-solving, and communication skills. Preferred Certifications

One or more of the following certifications is strongly preferred, Experience with cloud environments and post-exploitation activities. Experience with Active Directory security assessments. Familiarity with FISMA compliance requirements. Experience supporting government or regulated industry clients. Proficiency with common offensive security tools and frameworks. COMPENSATION & BENEFITS

At SIXGEN, we are committed to fair and equitable compensation practices. Compensation for this role will be based on experience, qualifications, technical expertise, and overall alignment with the position.

Benefits & conditions

Employer-paid health insurance premiums (medical, dental, vision) for you and your family Employer-paid short/long term disability insurance and basic life/AD&D insurance 401K with a 4% employer contribution Professional development reimbursement options available (training, certification, education, etc) Flexible and remote work policies for most positions Flexible PTO and holiday schedule

About the company

SIXGEN’s mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and cutting-edge capabilities to uncover vulnerabilities, protect vital systems, and ensure operational superiority in an ever-evolving digital landscape.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

Videos

See all

Related articles

See all