Penetration Tester

Quzara Llc
Washington, DC, United States
4 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Shift work
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) PHP (Programming Language) Application Programming Interfaces (APIs) Business Logic Software System Penetration Testing Microsoft Azure C++ (Programming Language) Cyber Security Computer Networks Databases Perl (Programming Language)
+17 more
Python (Programming Language) Kali Linux Windows PowerShell Comptia Pentest+ CE Red Team (Cyber Security) Ruby Reverse Engineering Web Application Security SQL Databases Wireshark Web Applications Web Testing Scripting Cloud Platform System Information Technology Burpsuite Vulnerability Analysis

Job description

The Senior Penetration Tester will lead and execute advanced security assessments across web applications, APIs, internal networks, cloud environments, and client infrastructure. This role is responsible for planning and performing penetration tests and vulnerability assessments, simulating real-world attack scenarios, identifying security weaknesses, and translating findings into clear reports, risk assessments, and actionable recommendations for technical and leadership audiences. The Senior Penetration Tester will also support client coordination, report delivery, and debriefs while mentoring penetration testing team members and maintaining advanced expertise in security tools, scripting, networking, web application security, and emerging offensive security techniques., * Plan, create, and execute advanced penetration methods, scripts, and tests for the team, with a focus on Web Applications

  • Assess and test the security of internal networks and underlying application infrastructure.
  • Conduct penetration testing and vulnerability assessments on Azure cloud infrastructure and applications
  • Lead and mentor a team of penetration testers, providing guidance and sharing expertise
  • Carry out remote and on-site testing of client networks and infrastructure to expose security weaknesses
  • Simulate security breaches to assess a system’s relative security
  • Create detailed reports and recommendations based on findings, including uncovered security issues and associated risk levels
  • Present findings, risk assessments, and conclusions to management and other relevant parties
  • Maintain advanced knowledge of networking, cryptography, reverse engineering, web applications, operating systems databases
  • Possess expertise in various scripting and programming languages, including Python, SQL, C/C++, JavaScript, PHP, Java, and Ruby
  • Provide strong written and oral communication skills to effectively convey assessment results and potential weaknesses
  • Assist in penetration testing intake, coordination with client teams for scheduling and delivery of reports/debriefs.

Marginal Functions of the Job

  • Other duties as assigned

Normal Work Schedule

This is a full-time position. Standard business hours are Monday through Friday 8:30 AM to 5:30 PM. If your role falls within our Security Operations Center, you will be assigned a specific shift. As a result, your working schedule may require flexibility to cover any shift that falls within a 24/7 cycle, it may also change and rotate, including nights, weekends, and holidays.

Requirements

  • Required bachelor’s degree in cyber security, computer science, IT or a related field.
  • Required: A fundamental understanding and experience with business/application logic vulnerabilities.
  • Required: 6 years minimum work experience directly related to Red Team assessments, and/or penetration testing (intranet, internet, web, wireless, social engineering), with a focus on Web Application testing. Additional years of relevant experience may be considered in lieu of a bachelor’s degree.
  • Required: Must have an active OSCP+ certification in addition to one of the following:
  • CompTia PenTest+
  • CEH
  • CompTia CySa+
  • GCIH
  • GCFA
  • CISSP
  • Expertise with scripting languages (e.g., Python, PowerShell, Java, Perl, etc)
  • Expertise with API focused penetration testing.
  • Proficiency with penetration testing tools (Kali Linux, Binwalk, BurpSuite, Wireshark, etc)

Nice To Have:

  • Certification focuses on Web Application penetration testing.
  • i.e. eWPT, BSCP, etc
  • Relevant security research.
  • Accredited CVEs, research papers or contributions to the cyber security sphere.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

3:30 min

Falling in love with Ruby and creating Basecamp

David Heinemeier Hansson David Heinemeier Hansson +1 · Coffee With Developers

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all