> Markdown version of [/jobs/ext/2014593-application-offensive-security-consultant](https://www.wearedevelopers.com/jobs/ext/2014593-application-offensive-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Offensive Security Consultant - **Company:** The Pipe - **Location:** Jersey City, NJ, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Testing (Software), Application Programming Interfaces (APIs), Software System Penetration Testing, Burp Suite, Cyber Security, Internet Security, Open Web Application Security, Web Application Security, Web Applications, Web Testing, Software Security, Mitre Att&ck, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://www.careerbuilder.com/job-details/application-offensive-security-consultant-jersey-city-nj--6d3c9c31-7a72-46ab-8301-d61023cf0bcd ## About the Role * 6+ years of experience in web application security testing. * 4+ years of hands-on experience with penetration testing tools, such as: * + Burp Suite + OWASP ZAP * Strong understanding of: * + OWASP Top 10 vulnerabilities + MITRE ATT&CK Framework * Ability to manually discover vulnerabilities beyond automated scanning. * Bachelors degree in a relevant field or equivalent experience. Preferred Qualifications (Nice to Have) * Certifications in offensive security/penetration testing, such as: * + OSCP (Offensive Security Certified Professional) + CEH (Certified Ethical Hacker) * Experience in Red Teaming and Adversarial Testing. * Active participation in Capture the Flag (CTF) competitions or platforms like TryHackMe, HackTheBox. * Ability to work under pressure, manage multiple tasks, and adapt to dynamic security challenges. Skills: Application Programming Interface (API), Applications Security, Best Practices, CEH - Certified Ethical Hacker, Computer Security, Financial Trend Analysis, Internet Application, Internet Security, Multitasking, Penetration Testing, Risk, Risk Management, Security Analysis, Security Architecture, Security Attacks, Security Consulting, Software Testing, Testing, Threat and risk analysis (TRA), Vulnerability Scanners, Web Testing ## Description Join our Application Security team as part of our Technology Risk initiative to support offensive security assessments and provide expert guidance on key projects. As an Application Offensive Security Consultant, you will be responsible for penetration testing, security assessments, and vulnerability identification across applications and APIs., * Conduct offensive security testing on applications and APIs. * Perform manual penetration testing to identify vulnerabilities beyond automated scans. * Evaluate application threats and assess security risks. * Provide detailed vulnerability reports with remediation recommendations. * Collaborate with Security Architects, Product Managers, and Risk Managers to implement security best practices. * Stay updated on emerging attack methodologies and security trends. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof](https://www.wearedevelopers.com/videos/1792-developer-time-is-valuable-use-the-right-tools-kilian-valkhof) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [A Practical Guide to Reducing Bundle Size](https://www.wearedevelopers.com/videos/1439-a-practical-guide-to-reducing-bundle-size) - [Decoding web accessibility through audit](https://www.wearedevelopers.com/videos/507-decoding-web-accessibility-through-audit) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [11 Best Practices For PHP Security](https://www.wearedevelopers.com/magazine/90-11-best-practices-for-php-security) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)