> Markdown version of [/jobs/ext/2942053-ethical-hacker-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2942053-ethical-hacker-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Ethical Hacker / Penetration Tester- - **Company:** MKS2 Technologies - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $120,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Proxy Servers, Applications Architecture, Software System Penetration Testing, Authentication Protocols, Bash Shell, Burp Suite, Cloud Computing Security, Cyber Security, Mobile Application Software, Information Systems Security Architecture Professional, Java Security, Java Web Services, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Fortify (Software), Secure Coding, Web Application Security, Session Management, Software Engineering, SQL Injection, Software Vulnerability Management, Web Applications, Scripting, Java Application Server, Enterprise Software Applications, Software Security, Mitre Att&ck, Caching, Cross-Site Scripting (XSS), GWAPT, Information Technology, Metasploit, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8002cfe88cf2acec ## About the Role * Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related technical field. * Minimum of 6 years of software development and security experience. * Prior experience in a DevSecOps, Application Security, Security Engineering, or Penetration Testing role. * Strong hands-on Java development experience. * Experience supporting large-scale enterprise applications. * Knowledge of secure coding principles and application security best practices. * Experience performing penetration testing against web applications and services. * Strong understanding of OWASP Top 10 vulnerabilities and mitigation techniques. * Experience with security testing tools such as: + Burp Suite + Metasploit + Web Proxy Tools + Vulnerability Assessment Platforms * Experience using Static and Dynamic Application Security Testing tools, including: + Fortify on Demand (SAST) + Fortify on Demand (DAST) * Knowledge of common web vulnerabilities including: + SQL Injection + Cross-Site Scripting (XSS) + Authentication & Authorization Flaws + Session Management Vulnerabilities + API Security Risks * Strong understanding of cryptography and secure communications protocols (SSL/TLS). * Excellent analytical, troubleshooting, and problem-solving skills. * Strong written and verbal communication abilities. * Demonstrated professionalism, ethics, and confidentiality., * OSCP (Offensive Security Certified Professional) * GWAPT (GIAC Web Application Penetration Tester) * GXPN (GIAC Exploit Researcher and Advanced Penetration Tester) * GPEN (GIAC Penetration Tester) * LPT (Licensed Penetration Tester) * CEH (Certified Ethical Hacker) * CISSP (Certified Information Systems Security Professional) * Experience with Python, Bash, or other scripting languages. * Experience performing secure code reviews for Java applications. * Knowledge of cloud security testing methodologies. * Mobile application penetration testing experience. * Experience conducting API security assessments. * Familiarity with HIPAA and regulated environments. * Knowledge of vulnerability management and CVE remediation processes. Desired Technical Expertise * Java Security * Secure Coding Practices * Application Security * Penetration Testing * Vulnerability Assessments * OWASP * MITRE ATT&CK Framework * SAST/DAST * DevSecOps * Web Application Security * API Security Testing * Threat Modeling * Risk Assessment ## Description We are seeking an experienced Ethical Hacker / Penetration Tester Principal to join a high-impact cybersecurity team supporting a large-scale enterprise application environment. This role focuses on identifying, exploiting, assessing, and remediating vulnerabilities within Java-based applications and supporting infrastructure. The ideal candidate possesses deep expertise in application security, penetration testing, secure coding practices, and DevSecOps methodologies. This position requires collaboration with development, testing, and security teams to proactively identify security weaknesses and strengthen application defenses throughout the Software Development Life Cycle (SDLC)., * Conduct penetration testing and vulnerability assessments of Java applications, APIs, and supporting infrastructure. * Perform manual and automated security testing to identify application vulnerabilities. * Develop and execute custom exploits to simulate real-world attacker techniques. * Analyze application architecture and code to identify security risks and attack vectors. * Collaborate with development teams to integrate security early in the SDLC. * Partner with QA and automation teams to incorporate security testing into release processes. * Review source code and provide secure coding guidance for remediation efforts. * Assess browser tokens, session management, caching, and authentication mechanisms. * Manipulate URLs, query parameters, browser data, and application workflows to identify exploitation opportunities. * Assist in incident response activities related to security vulnerabilities and published CVEs. * Create detailed reports outlining findings, risk levels, business impacts, and remediation recommendations. * Present security findings to both technical and non-technical stakeholders. * Contribute to security standards, policies, and secure development practices. * Stay current on emerging threats, attack techniques, and industry best practices. * Apply methodologies aligned with the MITRE ATT&CK Framework and OWASP guidelines. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [HTTP headers that make your website go faster](https://www.wearedevelopers.com/videos/1676-http-headers-that-make-your-website-go-faster) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Event based cache invalidation in GraphQL](https://www.wearedevelopers.com/videos/433-event-based-cache-invalidation-in-graphql) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)