Penetration Tester

Deloitte T.T.L.
Cincinnati, OH, United States
2 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Software System Penetration Testing Application Testing Automation of Tests Fat Client Mobile Application Software Kali Linux Nmap Open Web Application Security Cloud Services Swagger
+15 more
Reverse Engineering SQL Databases Web Services Scripting Postman Large Language Models Prompt Engineering Software Security Test Scripts Mitre Att&ck Metasploit Qualys Static Application Security Testing Programming Languages Dynamic Application Security Testing

Job description

Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.

Work you’ll do

This role is responsible for providing penetration testing services through a combination of technology and manual ingenuity as part of the Global cyber services organization for member firms.

Responsibilities of this role include:

  • Executing Penetration testing engagements:
  • Web Application Penetration Testing
  • Web Services / Application Programming Interface (API) Penetration Testing
  • AI/LLM Penetration testing
  • Network Penetration Testing
  • Mobile Application Penetration Testing
  • Thick Client Penetration Testing
  • Providing consultative guidance to customers on findings identified in a clear and actionable fashion, both in writing and verbally
  • Enhancing and updating testing methodologies, processes, and standards documentation
  • Leveraging AI and LLM-based tools and prompt engineering, using both established platforms and emerging frameworks, to accelerate reconnaissance and generate or refine testing scripts
  • Building, customizing, and maintaining AI-driven agents to automate recurring testing tasks
  • Continuously validating the accuracy and reliability of self-developed AI tools, actively working to reduce hallucinations and false positives in vulnerability identification
  • Evaluating and integrating emerging AI-assisted offensive security tooling into team methodology and playbooks
  • Proficient at analyzing and understanding complex architecture designs.
  • Ability to effectively communicate the services and capabilities our group can facilitate to our clients.

Requirements

Required:

  • Experienced with Kali Linux or other dedicated Penetration Testing OS Platform. With knowledge of common testing tools like Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and others
  • Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities
  • Familiarity with various AI models and frameworks from providers such as Anthropic and OpenAI, and experience configuring tools like Obsidian and Ollama is a plus for supporting other workflows.
  • Working knowledge of one scripting language and familiarity with at least one software programming language and framework
  • Demonstrated experience working with diverse stakeholders, preferably on a global multi-national basis
  • Ability to manage concurrent initiatives and use effective judgment in prioritization and time management
  • Strong written and verbal communication skills
  • Must be a US Citizen

Preferred:

  • Certified Ethical Hacker (CEH) Certification
  • Offensive Certified Security Professional (OSCP) Certification
  • Any GIAC Certification (GSEC, GWAB, GPEN, GMOB, GCPN)
  • OWASP Application Security Top 10
  • OWASP API Security Top 10
  • OWASP Thick Client Top 10
  • OWASP LLM Top 10
  • MITRE ATT&CK Framework
  • Cloud Service testing
  • Reverse Engineering
  • Static Application Software Testing (SAST)
  • Dynamic Application Testing (DAST)
  • Experience of Agentic development and its application to support penetration testing
  • Limited immigration sponsorship may be available. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

About the company

Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in “what is” but rather “what can be” to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas ¡ World Congress 2026 Europe

1:59 min

Designing governed and AI-native API platforms

Gbadebo Bello Gbadebo Bello ¡ Europe 2026 Virtual

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher ¡ LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

1:16 min

Automating documentation and code generation with OpenAPI standards

James Seconde ¡ World Congress 2023

1:59 min

Tools for API documentation and relationship visualization

Alen Pokos ¡ LIVE

Videos

See all

Related articles

See all