Senior Security Consultant (Web Application Penetration Tester)

NetSPI, LLC
Minneapolis, MN, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Shift work
Job source

Tech stack

C (Programming Language) Java (Programming Language) Application Programming Interfaces (APIs) Apple Mac Systems Software System Penetration Testing Burp Suite C Sharp (Programming Language) C++ (Programming Language) CompTIA Security+ Computer Programming Linux Perl (Programming Language)
+12 more
Python (Programming Language) Kali Linux Open Web Application Security Ruby Web Applications Scripting Mitre Att&ck GWAPT Information Technology Metasploit Nessus Workday

Job description

  • Conduct engagements on web applications and underlying APIs independently and provide technical oversight

  • Review reports for accuracy in technical oversight, perform weekly QA oversight, and provide mentoring support to others

  • Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture

  • Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes

  • Participate in development, implementation, and oversight of testing, delivery, and management strategies for key client accounts

  • Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations.

Requirements

Do you have experience in macOS?, Join the mission as a Senior Security Consultant. We are seeking a skilled and detail-oriented Penetration Tester to conduct thorough security assessments, identify vulnerabilities, and provide expert recommendations to strengthen our clients’ security posture. As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices., * Bachelor’s degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience

  • Minimum of 3-5 years of work experience in Penetration Testing

  • Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus)

  • Familiarity with offensive and defensive IT concepts and protocols

  • Extensive understanding of the OWASP Top 10, MITRE ATT&CK framework, and various security frameworks.

  • Working knowledge of Windows, Linux and MacOS operating systems internals

  • Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences

  • Ability to work independently and as part of a team

  • Proficient communication skills, both written and verbal

  • Willingness to travel up to 5-10%

  • This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs

Preferred Qualifications:

  • Ability to provide technical and QA oversight on web applications and underlying APIs.

  • Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)

  • Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, GWAPT)

About the company

NetSPI® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts. Specializing in 50+ pentest types, attack surface visibility, vulnerability prioritization, and attack simulation, NetSPI delivers security testing with unprecedented clarity, speed, and scale.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at www.netspi.com/careers (http://www.netspi.com/careers).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

3:30 min

Falling in love with Ruby and creating Basecamp

David Heinemeier Hansson David Heinemeier Hansson +1 · Coffee With Developers

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

Videos

See all

Related articles

See all