Назад
Company hidden
2 дня назад

Penetration Tester (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Penetration Tester (Cybersecurity) (Web, Mobile, API): Performing expert-level penetration testing and application security assessments across web applications, mobile applications, thick clients, and APIs with an accent on source code review, reverse engineering, and OWASP-based testing. Focus on chaining application flaws, proving business impact, identifying AI/LLM weaknesses, and communicating remediation guidance to both technical and executive audiences.

Location: Fully remote, but candidates must be located in Florida.

Company

hirify.global provides expert-level penetration testing services designed to identify overlooked vulnerabilities and improve client security.

What you will do

  • Perform penetration tests of web applications, mobile applications, thick clients, and APIs.
  • Conduct source code reviews and white-box testing to prove the impact of application flaws.
  • Reverse-engineer mobile and thick-client applications and chain vulnerabilities across application, cloud, and on-premises Active Directory environments.
  • Perform SAST and DAST assessments, validate scanner results, and eliminate false positives.
  • Prepare detailed findings and remediation reports and debrief results for technical and executive audiences.
  • Apply OWASP principles across web, API, mobile, and AI/LLM security testing.

Requirements

  • Must be located in Florida.
  • 3–5 years of experience in penetration testing and consulting, with at least two years handling information security-related tasks.
  • Strong programming knowledge in C, C#, Python, Objective-C, Java, JavaScript, SQL, and AngularJS.
  • Experience with web services and data formats including XML, JSON, SOAP, REST, and AJAX.
  • Extensive experience using an attack proxy such as Burp Suite; OSCP or Burp Suite is mandatory.
  • Post-secondary college or university degree and a strong understanding of application, web, API, mobile, and AI/LLM security weaknesses.

Nice to have

  • Professional qualifications such as OSCP, OSWE, or BSCP.

Culture & Benefits

  • Fully remote work within Florida.
  • Customer-first, highly communicative consulting environment.
  • Focus on continuous learning, self-motivation, dependability, and high-quality deliverables.
  • Employee growth and development opportunities.
  • Competitive compensation with performance-based pay.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →