Penetration Tester (Florida)

Packetlabs
United States
29 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Ajax (Programming Language) Software System Penetration Testing Burp Suite Software as a Service Cyber Security Electronic Data Interchange (EDI) Fat Client JSON Open Web Application Security Reverse Engineering
+8 more
Simple Object Access Protocol (SOAP) Web Services Extensible Markup Language (XML) Large Language Models Software Security Restful APIs Static Application Security Testing Dynamic Application Security Testing

Job description

  • Your primary role is to perform penetration testing of web applications, mobile applications, thick clients, and APIs.
  • Source code review and whitebox penetration testing to prove the impact of application flaws.
  • Reverse engineering of mobile and thick client applications.
  • You sometimes chain application flaws to other areas, such as cloud and on-prem AD infrastructure. Opportunities for lateral movement into the infrastructure teams are limited and given at the manager’s discretion.
  • Develop detailed reports on findings and remediations for impactful findings. You will learn to debrief these findings at both a technical and executive level.
  • Perform SAST and DAST on enterprise, SaaS, and custom in-house applications.
  • Experience in using scanners and knowledge of validation and elimination of false positives.
  • A strong understanding of OWASP in Web, API, Mobile, and AI/LLM is necessary, but you will be asked to go beyond.

Requirements

  • You have a customer-first mentality. Is a great communicator with clients, project managers, and teammates. Rapid responses and on time.
  • You deliver work that you take pride in. Your work is an autograph of your excellence.
  • You dig deeper into every finding. Doesn’t stop until impact is proven.
  • You are comfortable being uncomfortable. Goes towards obstacles, not away from them. Consulting isn’t your typical job and requires adapting to rapidly changing environments.
  • You are always learning. Cybersecurity is changing every day, and you need to keep up or want to keep up. Be deeply aware of your skillset and be willing to improve.
  • You are Self-motivated and dependable., o Solid working knowledge of programming languages, including C, C#, Python, Objective-C, Java, JavaScript, SQL, and frameworks like AngularJS. o Familiarity with web services and data exchange formats such as XML, JSON, SOAP, REST, and AJAX. o Understanding of AI/LLM weaknesses and flaws in applications. o Extensive experience/expertise in using an attack proxy (e.g. Burp Suite)

  • Preferred if you have 3 - 5 years of experience working in penetration testing and consulting
  • A graduate of a post-secondary college or university degree program.
  • Has at least two years of experience dealing with information security-related tasks.
  • Has professional qualifications (one or more): OSCP, OSWE, BSCP.

Benefits & conditions

  • Competitive compensation and pay for performance
  • Employee growth and development
  • Fully remote (in Florida)

About the company

Packetlabs was built by an ethical hacker after seeing vulnerability assessments presented as penetration tests. Our slogan “Ready for more than a VA scan?” drives at the importance of not providing our clients with a false sense of security.

We are a passionate team of highly trained, proactive, penetration testers. We provide expert-level penetration testing services that are thorough and tailored to help foster a safe digital space where everyone has the right to privacy and security. Packetlabs consultants find weaknesses others overlook and continuously learn new ways to evade controls. We hold ourselves to a very high standard.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · World Congress 2025

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

Videos

See all

Related articles

See all