
Manual Penetration Testers
Jobs via Dice • United States
Role & seniority
- Senior/experienced Manual Penetration Tester
Stack/tools
Platforms: APIs (REST/SOAP), Web Applications, Mobile applications, thick client
Tools: Burp Suite Pro, Netsparker
Methods: threat modeling, application architecture reviews, POC development/exploitation
Top 3 responsibilities
-
Conduct manual penetration testing across APIs, web/mobile/thick client applications
-
Perform threat modeling, evaluate business logic, and review application architecture
-
Present testing results to technical and non-technical audiences; guide remediation options; develop and demonstrate POCs
Must-have skills
-
5+ years of recent application penetration testing experience (APIs, web, mobile)
-
Ability to communicate reports and lead remediation discussions with diverse audiences
-
Proficiency with Burp Suite Pro and Netsparker
-
Bachelor’s degree or equivalent industry experience
Nice-to-haves
-
Major ethical hacking certifications (GWAPT, CREST, OSWE, OSWA) – preferred but not required
-
Demonstrated ability to perform objective-based, abstract testing engagements and real-time demos
Location & work type
Location: Remote
Work type: Full-time/contract as listed by client (remote engagement)
Full Description
Dice is the leading career destination for tech experts at every stage of their careers. Our client, Georgia IT, is seeking the following. Apply via Dice today!
Manual Penetration Testers
Location: Remote
Responsibilities
Perform manual Application penetration testing against API’s (REST/SOAP), Web Applications, Mobile applications, and thick client applications Perform threat modeling, evaluate application business logic, and perform application architecture reviews Ability to demonstrate application testing experience in real time via demos to both internal and external audiences Ability to perform objective based, abstract penetration testing engagements Ability to develop and exploit POCs Act independently in penetration testing engagements, with minimal oversight and guidance Engage with technical and non-technical audiences to articulate both testing processes, techniques and results; guide technical audiences on remediation options and assist clients in weighing those options
Qualifications
Minimum 5 years of recent experience in application penetration testing of API’s, web applications and mobile applications Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations Experience with burp suite pro, and other app testing tools such as Netsparker Bachelor''s degree from an accredited college/university or equivalent industry experience One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA