> Markdown version of [/jobs/ext/599966-senior-security-consultant-web-application-penetration-tester](https://www.wearedevelopers.com/jobs/ext/599966-senior-security-consultant-web-application-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Consultant (Web Application Penetration Tester) - **Company:** NetSPI, LLC - **Location:** Minneapolis, MN, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), Application Programming Interfaces (APIs), Apple Mac Systems, Software System Penetration Testing, Burp Suite, C Sharp (Programming Language), C++ (Programming Language), CompTIA Security+, Computer Programming, Linux, Perl (Programming Language), Python (Programming Language), Kali Linux, Open Web Application Security, Ruby, Web Applications, Scripting, Mitre Att&ck, GWAPT, Information Technology, Metasploit, Nessus, Workday - **Published:** June 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=067e7ec0a9e14957 ## About the Role Do you have experience in macOS?, Join the mission as a Senior Security Consultant. We are seeking a skilled and detail-oriented Penetration Tester to conduct thorough security assessments, identify vulnerabilities, and provide expert recommendations to strengthen our clients' security posture. As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices., * Bachelor's degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience * Minimum of 3-5 years of work experience in Penetration Testing * Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus) * Familiarity with offensive and defensive IT concepts and protocols * Extensive understanding of the OWASP Top 10, MITRE ATT&CK framework, and various security frameworks. * Working knowledge of Windows, Linux and MacOS operating systems internals * Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences * Ability to work independently and as part of a team * Proficient communication skills, both written and verbal * Willingness to travel up to 5-10% * This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs Preferred Qualifications: * Ability to provide technical and QA oversight on web applications and underlying APIs. * Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#) * Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, GWAPT) ## Description * Conduct engagements on web applications and underlying APIs independently and provide technical oversight * Review reports for accuracy in technical oversight, perform weekly QA oversight, and provide mentoring support to others * Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture * Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes * Participate in development, implementation, and oversight of testing, delivery, and management strategies for key client accounts * Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Fireside Chat with Werner Vogels, VP & CTO, Amazon.com & Daniel Gebler, CTO at Picnic](https://www.wearedevelopers.com/videos/1405-fireside-chat-with-werner-vogels-vp-cto-amazon-com-daniel-gebler-cto-at-picnic) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)