> Markdown version of [/jobs/ext/209340-senior-web-application-penetration-tester](https://www.wearedevelopers.com/jobs/ext/209340-senior-web-application-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Web Application Penetration Tester - **Company:** SixGen, Inc - **Location:** Northern Virginia, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $100,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), PHP (Programming Language), Application Programming Interfaces (APIs), Software System Penetration Testing, Cloud Computing, Databases, Mobile Application Software, Python (Programming Language), Kali Linux, Nmap, Open Source Technology, Penetration Tools, Web Applications, Web Testing, SC Clearance, GWAPT, Metasploit, Nessus, Cyber Warfare, Burpsuite, Vulnerability Analysis - **Published:** May 15, 2026 - **Apply:** https://www.careerjet.com/jobad/usf5b874e29f85a46051bd92c95d85644a ## About the Role * Ability to participate in cybersecurity control testing engagements for the customer's network, websites, apps and cloud technologies. * 5 years of Web Application Penetration Tester experience. * OSCP, OSWA, OSWE, CRTO, CBBH, GWAPT, or other relevant, hands-on certification. OSCP preferred. * Must have experience in web application penetration testing. * Knowledge of FISMA and NIST 800 series standards. * Experience in network mapping, vulnerability scanning, and penetration and web application testing. * Experience using approved test protocols and procedures to conduct network and application-level penetration tests. * Experience attending client meetings, recording internal and technical client interviews and preserving the contents of reports and memoranda. * Proficiency in using scanning tools like Nessus and NMap, as well as penetration tools like the Kali Linux suite, Burpsuite and Metasploit. * Must be willing to travel as needed. * Must be able to obtain Secret Clearance. * Experience in script writing and crafting of payloads. ## Description We are seeking a Senior Web Application Penetration Tester to join our growing team. As a Senior Web Application Penetration Tester, you will be challenged to perform endpoint discovery, open source research, web application enumeration, and novel vulnerability analysis/exploitation. This is much more than Burp scans; operators routinely develop custom tooling (in languages such as PHP, Java, and Python) and achieve a deep understanding of target infrastructure/technology in exploitation paths. The assessments are usually a long haul and great for advanced bug bounty hunters who enjoy getting deep in the weeds. Some cloud/Active Directory experience is a plus for post exploitation activities. This role resides in our Delivery Department and reports to our VP of Cyber Operations. This position is remote with a 10% travel requirement. SIXGEN supports cyber and intelligence missions by serving government and commercial organizations as they overcome global cybersecurity challenges. Our highly skilled operators conduct research and assessments based on real-world threats. We simulate adversaries and malicious actors to report details and actionable findings on critical assets and infrastructures. Our program planners advise mission owners to bring rapid solutions to intelligence mission leaders. Using innovative processes, tools, and techniques, we predict and overcome cybersecurity vulnerabilities. Our successes are supported by our diverse team of experienced, technical talent. SIXGEN is growing our support to mission by adding an ambitious Strategic Management Consultant to our team. SIXGEN, Inc. is an Equal Opportunity/Veterans/Disabled Employer. Core Responsibilities: * Conduct assessments of web applications, mobile applications, databases, client-side applications and tools, and APIs. * Collaborate with team members and clients to define project scopes, business cases, review test results, and determine remediation steps. * Analyze security findings, including risk analysis and root cause analysis. * Draft reports and communicate complex security concepts and test findings to clients and stakeholders. * Participate in client meetings, communicate clearly and openly on incremental progress, and inform the team of any help needed on impediments and roadblocks. Generate comprehensive reports, including detailed findings, exploitation procedures, and mitigation. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)