Penetration Tester

Amatriot Group, LLC
Rensselaer, NY, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$90,000.0 - $105,000.0
Working hours
Regular working hours
Job source

Tech stack

Testing (Software) Java (Programming Language) Applications Architecture Software System Penetration Testing Bash Shell Burp Suite Cloud Computing Security Cyber Security Mobile Application Software Java Security Python (Programming Language) Open Web Application Security
+17 more
Fortify (Software) Secure Coding Web Application Security SQL Injection Software Vulnerability Management Scripting Java Application Server Software Security Mitre Att&ck GWAPT Information Technology Metasploit Cybercrime Api Management Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

A Penetration Tester with a focus on Java application security identifies, exploits, and supports remediation of vulnerabilities in Java applications to help guard against cyber threats., * Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.

  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Manipulate URLs, query parameters, and application browser data to identify penetration avenues.
  • Validate and assess browser tokens, cache manipulation, and production versus non-production architecture.
  • Assist in responding to security incidents related to Java vulnerabilities and current published NIST CVEs., * Collaborate with development teams to understand application architecture and identify security weaknesses early.
  • Collaborate with testing teams to integrate security testing with manual and automated testing.
  • Provide guidance on secure coding and vulnerability remediation.
  • Help improve secure development lifecycle processes.
  • Contribute to security policies for Java development and deployment.

Reporting, Communication, and Threat Awareness

  • Clearly document and report findings, including technical details, risk assessments, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Stay updated on Java security threats and best practices.
  • Apply familiarity with the MITRE ATT&CK Framework.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field., * Minimum of 6 years of development or security experience. [Required]
  • Experience in penetration testing or ethical hacking with a focus on Java application security.
  • Experience with penetration testing tools such as Burp Suite and Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools., * Strong knowledge of Java programming and Java security practices.
  • Scripting experience.
  • Proficiency in web application security principles, including OWASP.
  • Knowledge of common web vulnerabilities, including SQL injection and cross-site scripting, and exploit techniques.
  • Strong understanding of cryptography and secure communication protocols, including SSL/TLS.
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.
  • Familiarity with the MITRE ATT&CK Framework., * Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or other industry security certifications.
  • Experience with scripting languages, such as Python or Bash.
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations such as HIPAA.
  • Experience with API testing.

Benefits & conditions

4.14.1 out of 5 stars 327 Columbia Turnpike, Rensselaer, NY 12144 Hybrid work $90,000 - $105,000 a year - Full-time

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

2:13 min

Bolstering test coverage consistently without specialized security frameworks

Ramona Schwering Ramona Schwering · World Congress 2024

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all