Application Offensive Security Consultant

The Pipe
Jersey City, NJ, United States
10 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Testing (Software) Application Programming Interfaces (APIs) Software System Penetration Testing Burp Suite Cyber Security Internet Security Open Web Application Security Web Application Security Web Applications Web Testing Software Security Mitre Att&ck
+1 more
Vulnerability Analysis

Job description

Join our Application Security team as part of our Technology Risk initiative to support offensive security assessments and provide expert guidance on key projects. As an Application Offensive Security Consultant, you will be responsible for penetration testing, security assessments, and vulnerability identification across applications and APIs., * Conduct offensive security testing on applications and APIs.

  • Perform manual penetration testing to identify vulnerabilities beyond automated scans.
  • Evaluate application threats and assess security risks.
  • Provide detailed vulnerability reports with remediation recommendations.
  • Collaborate with Security Architects, Product Managers, and Risk Managers to implement security best practices.
  • Stay updated on emerging attack methodologies and security trends.

Requirements

  • 6+ years of experience in web application security testing.
  • 4+ years of hands-on experience with penetration testing tools, such as: *

  • Burp Suite
  • OWASP ZAP
  • Strong understanding of: *

  • OWASP Top 10 vulnerabilities
  • MITRE ATT&CK Framework
  • Ability to manually discover vulnerabilities beyond automated scanning.
  • Bachelors degree in a relevant field or equivalent experience.

Preferred Qualifications (Nice to Have)

  • Certifications in offensive security/penetration testing, such as: *

  • OSCP (Offensive Security Certified Professional)
  • CEH (Certified Ethical Hacker)
  • Experience in Red Teaming and Adversarial Testing.
  • Active participation in Capture the Flag (CTF) competitions or platforms like TryHackMe, HackTheBox.
  • Ability to work under pressure, manage multiple tasks, and adapt to dynamic security challenges.

Skills: Application Programming Interface (API), Applications Security, Best Practices, CEH - Certified Ethical Hacker, Computer Security, Financial Trend Analysis, Internet Application, Internet Security, Multitasking, Penetration Testing, Risk, Risk Management, Security Analysis, Security Architecture, Security Attacks, Security Consulting, Software Testing, Testing, Threat and risk analysis (TRA), Vulnerability Scanners, Web Testing

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

7:35 min

Addressing inconsistent screen reader and browser environments

Dirk Ginader · LIVE

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

Videos

See all

Related articles

See all