VAPT Specialist

ControlCase, LLC
United States
3 months ago
Apply on controlcase.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Red Team (Cyber Security) Web Applications GWAPT

Job description

As a Vulnerability Assessment and Penetration Testing Specialist, you will conduct authorized penetration tests on computer systems to identify vulnerabilities that could be exploited. You may choose to specialize in areas such as:

  • Networks and Infrastructure
  • Operating Systems (Windows, Linux, and macOS)
  • Web and Mobile Applications
  • APIs and Web Services

The VAPT Lead role will be a blend of approximately 80% penetration testing and 20% project management. It will also involve understanding complex computer systems and technical cybersecurity terminology., * Collaborating with clients to identify their testing requirements, such as the number and type of systems to be tested.

  • Planning and developing penetration testing methods, scripts, and tests.
  • Conducting remote tests on clients’ networks or on-site infrastructure tests to uncover security weaknesses.
  • Simulating security breaches to evaluate system vulnerabilities.
  • Preparing detailed reports and recommendations, including identified security issues and their risk levels.
  • Providing actionable advice on mitigating risks and implementing solutions to strengthen system security.
  • Presenting findings, risks, and recommendations to management and other stakeholders.
  • Assessing the business and user impact of identified vulnerabilities.
  • Analyzing how unresolved security flaws could affect business functions.
  • Leading and managing a team of 5-6 members, fostering collaboration and expertise., At ControlCase, we are committed to supporting our employees’ success and well-being. We offer a comprehensive range of benefits designed to promote work-life balance and foster professional growth, along with the exciting opportunity to collaborate with an international team across various regions., This is a fully remote position, offering flexibility to work from home. You’ll be part of a dynamic international company, ControlCase, collaborating via virtual meetings and teams. You’ll manage your own schedule, meet deadlines, and contribute to ControlCase’s innovative global efforts in cybersecurity and compliance.

Requirements

  • 4-5+ years of relevant experience
  • US Citizenship or Green Card holder
  • Ability to travel to client sites, * Bachelor’s degree preferred
  • Preferred Certifications:
  • OSCP - Offensive Security Certified Professional
  • CPSA - CREST Practitioner Security Analyst
  • CRT - CREST Registered Tester
  • CRTO - Certified Red Team Operator
  • CRTP - Certified Red Team Professional
  • GWAPT - GIAC Web Application Penetration Tester
  • GPEN - GIAC Penetration Tester
  • GIAC - Global Information Assurance Certification

Benefits & conditions

  • Company-Provided Equipment: Essential tools for success, including a computer, to support your work.
  • 401(k) Plan: Competitive retirement savings options to help you plan for the future.
  • Health Insurance: Comprehensive medical coverage for you and your family.
  • Dental & Vision Insurance: Access to dental and vision care to keep you healthy.
  • 100% Company Paid Life Insurance: Peace of mind with life insurance coverage.
  • Paid Time Off (PTO): Generous paid time off and official holidays to recharge.
  • Mileage & Travel Reimbursement: For business-related travel and mileage.
  • Cell Phone & Internet Reimbursement: Stay connected with monthly reimbursements for phone and internet costs.
  • Employee Assistance Program (EAP): Access to resources for mental health, counseling, and personal support.
  • Flexible Spending Account (FSA): Save on healthcare and dependent care expenses.
  • Employee Discount Program: Enjoy discounts at select partners and vendors.
  • Referral Program: Earn rewards for referring talented candidates to join our team.

About the company

ControlCase is a global leader in certification, cybersecurity, and continuous compliance services. We are dedicated to helping organizations develop and implement streamlined, cost-effective, and comprehensive information security and compliance programs for both on-premise and cloud environments. Our services cater to industries needing compliance with standards such as PCI DSS, HITRUST, SOC 2 Type II, ISO 27001, PCI PIN, PCI P2PE, PCI TSP, PA DSS, CSA STAR, HIPAA, GDPR, SWIFT, CMMC, and FedRAMP.

Headquartered in Fairfax, Virginia, ControlCase operates worldwide, with locations across North America, Europe, Latin America, Asia/Pacific, and the Middle East. We provide innovative Compliance as a Service (CaaS) solutions, enabling businesses to efficiently meet regulatory compliance requirements in a cost-effective manner.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on controlcase.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

1:19 min

Enhancing product safety through continual red teaming operations

Rebekka Weiss Rebekka Weiss +1 · World Congress 2025

6:13 min

Analyzing test coverage gaps in standard web applications

Jorge Gonzalez Pliego Jorge Gonzalez Pliego · Europe 2026 Virtual

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

1:36 min

Running AI applications with PWAs and background web workers

Maxim Salnikov Maxim Salnikov · World Congress 2025

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

Videos

See all

Related articles

See all