Security Engineer - Pentesting

Randstad
Brooklyn Park, MN, United States
1 day ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$186,888.0 - $193,128.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Software System Penetration Testing Automation of Tests Burp Suite Cyber Security Mobile Application Software Python (Programming Language) Nmap Open Web Application Security PCI Data Security Standards Software Vulnerability Management Web Applications
+3 more
Scripting Software Security Information Technology

Job description

We are seeking a Security Engineer to join our enterprise Cyber Security team. In this role, you will play a key part in safeguarding complex web applications and APIs through comprehensive penetration testing and threat analysis. You will collaborate directly with engineering teams to identify vulnerabilities, develop automation tools, and implement robust security remediations., * Execute end-to-end penetration tests covering scoping, exploitation, validation, and reporting for web applications and APIs.

  • Identify web application vulnerabilities such as OWASP Top 10, injection attacks, and authentication/authorization flaws.
  • Utilize advanced security testing tools, including Burp Suite, Nmap, and common exploitation frameworks.
  • Write custom scripts and automations in Python or Go to streamline security testing workflows.
  • Partner directly with engineering teams to validate security findings and provide actionable remediation guidance.
  • Document comprehensive technical findings and support threat modeling to identify risk areas pre-deployment.

Requirements

Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience with 7+ years in cybersecurity.

5+ years of hands-on penetration testing experience specifically targeting web applications and APIs.

Advanced expertise with security testing tools, including Burp Suite and Nmap, along with strong scripting skills in Python or Go.

PREFERRED QUALIFICATIONS

Professional certifications such as OSCP, OSCE, OSWE, or CISSP.

Experience testing mobile apps, hardware, embedded systems, or third-party vendor solutions.

Familiarity with PCI compliance penetration testing requirements and bug bounty program management.

skills:

APIs,Burp Suite,cybersecurity professional,Mobile application,Nmap,Python,application security,penetration testing,vulnerability management,web applications,excellent communication skills,Scripting & Automation,CISSP,embedded systems,bug bounty,OSCE,risk identification,risks,Security,Security Testing Tools,technical proficiency,threat modeling

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

Videos

See all

Related articles

See all