Black Nova Venture Capital logo

Web Application Penetration Tester - Nullify

Black Nova Venture Capital Sydney, New South Wales, Australia

remote
Posted Aug 27, 2026Apply by Sep 26, 2026

**Role & seniority: ** Security Engineer / Web Application Penetration Tester (human-led “edge” validating and expanding autonomous security coverage)

**Stack/tools: **

  • Web app security testing (manual pentesting)

  • Code review & request tracing

  • Custom tooling when needed

  • OWASP Top 10–aligned testing

  • Top 3 responsibilities:

    • Perform deep manual pentests on customer-facing web apps, focusing on gaps automation misses (auth flows, business logic, multi-step exploit chains).

    • Convert novel findings into reproducible techniques and feed them back into Nullify’s detection/validation agents.

    • Collaborate with customer security teams throughout engagements (scoping to report-back).

  • Must-have skills:

    • Hands-on experience exploiting vulnerabilities in production web applications.

    • Strong understanding of OWASP Top 10 and related vulnerability classes.

    • Ability to validate findings with proof (avoid speculation).

    • Comfort reading application code, tracing requests, and debugging test assumptions; build custom tooling as required.

  • Nice-to-haves:

    • Experience training or evaluating AI systems on security tasks.

    • Ability to keep current with new web frameworks, auth patterns, and emerging vulnerability classes.

  • Location & work type: Not specified in the provided text.

Full Description

Nullify runs autonomous security work most teams can't staff for. This role is the human edge of that — validating what our agents find, going after what they can't, and feeding every technique back into the system so it gets sharper.

What You'll Do

Run deep, manual web app pentests against customer surface area that automated scanning alone won't catch — auth flows, business logic, multi-step exploit chains. Turn novel findings into reproducible techniques that get encoded back into Nullify's detection and validation agents. Partner with customer security teams during engagements, from scoping through report-back.

Keep pace with the frontier: new frameworks, new auth patterns, new classes of vulnerability.

What You Bring

Real-world experience finding and exploiting vulnerabilities in production web applications — OWASP Top 10 and beyond.

Comfort working close to the metal: reading application code, tracing requests, building custom tooling when off-the-shelf doesn't cut it. A bias toward proof over speculation — you validate before you report.

Bonus: experience training or evaluating AI systems on security tasks.

Web Application Penetration TestingOWASP Top 10Business Logic TestingExploit Chain DevelopmentCustom ToolingApplication Code AnalysisVulnerability ValidationAI Security Evaluationmulti-locationreview:company

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.