Senior Penetration Tester / Application Security Engineer
- Location
- Remote
- Employment
- Part-time
- Level
- Specialist
- Category
- QA & Testing
- Posted
Description
We are looking for a Senior Penetration Tester / Application Security Engineer to perform a comprehensive security assessment of a web application and its APIs.
Project start: approximately Q4
Engagement: project-based / part-time
Main scope: Web Application & API Penetration Testing
Tech Stack
Drupal with significant custom development
Vue.js frontend and admin panel
Java backend
MongoDB
React Native for iOS and Android (mobile pentesting may be added later)
Responsibilities
Perform manual penetration testing of the web application and admin panel
Conduct API security testing
Test authentication, authorization, and role-based access controls
Identify business logic and security vulnerabilities
Assess the application against OWASP Top 10 and OWASP API Security risks
Prepare a professional penetration testing report with severity levels, vulnerability descriptions, evidence, and remediation recommendations
Requirements
Strong hands-on experience in Web Application and API Penetration Testing
Strong manual pentesting skills, not only automated scanning
Solid experience with Burp Suite and standard security testing tools
Experience testing custom-built web applications
Experience preparing professional pentest reports
Experience with Java, Drupal, or Vue.js is a plus
Mobile application pentesting experience is a plus, but not required
Apply at the source
This role was published by Dexis Development and listed via Djinni. Applications are handled there, not on this site.
Original posting: https://djinni.co/jobs/843653-senior-penetration-tester-application-securit/