# Senior Penetration Tester / Application Security Engineer — Dexis Development

Dexis Development

Location
Remote
Employment
Full-time
Level
Specialist
Category
QA & Testing
Posted

Description

Dexis Development is looking for a Senior Penetration Tester / Application Security Engineer for an upcoming European client project.

Start: Q4 2026

Format: Remote

Engagement: Project-based / part-time

Main scope: Web Application + Admin Panel + API Penetration Testing

## Project Stack

  • Drupal + significant custom code
  • Vue.js frontend
  • Vue.js admin panel
  • Java backend
  • MongoDB
  • React Native — iOS / Android *(mobile pentest may be added later)*

## Responsibilities

  • Manual Web Application and API penetration testing
  • Black-box, grey-box and white-box assessments
  • Authentication / authorization / RBAC testing
  • Business logic vulnerability testing
  • API security testing
  • Vulnerability validation and false-positive elimination
  • Remediation recommendations
  • Retesting after remediation when required
  • Preparation of professional client-facing pentest reports

## Required Experience

  • Strong experience in Web & API Penetration Testing
  • Strong manual pentesting skills — not only automated scanning
  • Strong knowledge of Burp Suite
  • OWASP Top 10
  • OWASP API Security Top 10
  • OWASP Web Security Testing Guide
  • PTES
  • Authentication, authorization and session security
  • Access-control and business logic vulnerabilities
  • Experience testing complex custom web applications
  • Experience preparing professional penetration testing reports

## Languages — Mandatory

  • English
  • Ukrainian or Russian — fluent

## Will Be a Plus

  • OSCP / OSWE / CREST
  • BSCP / GPEN / GWAPT or similar certifications
  • Experience with EU / enterprise clients
  • Java application security
  • Drupal security
  • Mobile / React Native pentesting
  • Cloud / infrastructure pentesting

## When Applying

Please include:

  • Relevant Web/API pentesting experience
  • Certifications
  • Location
  • Availability from Q4 2026
  • Hourly or daily rate
  • An anonymised sample pentest report, if available

Apply at the source

This role was published by Dexis Development and listed via Djinni. Applications are handled there, not on this site.

View & apply on djinni.co ↗