# Senior Penetration Tester / Application Security Engineer — Dexis Development
- Location
- Remote
- Employment
- Full-time
- Level
- Specialist
- Category
- QA & Testing
- Posted
Description
Dexis Development is looking for a Senior Penetration Tester / Application Security Engineer for an upcoming European client project.
Start: Q4 2026
Format: Remote
Engagement: Project-based / part-time
Main scope: Web Application + Admin Panel + API Penetration Testing
## Project Stack
- Drupal + significant custom code
- Vue.js frontend
- Vue.js admin panel
- Java backend
- MongoDB
- React Native — iOS / Android *(mobile pentest may be added later)*
## Responsibilities
- Manual Web Application and API penetration testing
- Black-box, grey-box and white-box assessments
- Authentication / authorization / RBAC testing
- Business logic vulnerability testing
- API security testing
- Vulnerability validation and false-positive elimination
- Remediation recommendations
- Retesting after remediation when required
- Preparation of professional client-facing pentest reports
## Required Experience
- Strong experience in Web & API Penetration Testing
- Strong manual pentesting skills — not only automated scanning
- Strong knowledge of Burp Suite
- OWASP Top 10
- OWASP API Security Top 10
- OWASP Web Security Testing Guide
- PTES
- Authentication, authorization and session security
- Access-control and business logic vulnerabilities
- Experience testing complex custom web applications
- Experience preparing professional penetration testing reports
## Languages — Mandatory
- English
- Ukrainian or Russian — fluent
## Will Be a Plus
- OSCP / OSWE / CREST
- BSCP / GPEN / GWAPT or similar certifications
- Experience with EU / enterprise clients
- Java application security
- Drupal security
- Mobile / React Native pentesting
- Cloud / infrastructure pentesting
## When Applying
Please include:
- Relevant Web/API pentesting experience
- Certifications
- Location
- Availability from Q4 2026
- Hourly or daily rate
- An anonymised sample pentest report, if available
Apply at the source
This role was published by Dexis Development and listed via Djinni. Applications are handled there, not on this site.
Original posting: https://djinni.co/jobs/844057-senior-penetration-tester-application-securit/