5+ years of experience planning, conducting, and managing web application penetration tests
Deep understanding of application security fundamentals, OWASP Top 10, common vulnerabilities, and secure development best practices
Experience assessing vulnerabilities and developing exploits across diverse targets
Strong understanding of system and network security, authentication protocols, security protocols, and applied cryptography
Ability to communicate complex technical findings clearly and provide practical remediation guidance to technical and executive audiences
Preferred Experience
Deep experience in at least one of the following
Cloud Security - Experience assessing AWS cloud environments, including technologies such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambda
Mobile Application Security - Experience testing iOS and/or Android applications, including mobile application architecture, API communication, data storage, authentication flows, and common mobile security vulnerabilities
Source Assisted Application Assessments: Experience evaluating applications across multiple layers, including source code, APIs, infrastructure, and integrations. Strong proficiency in Golang is highly preferred, along with familiarity in languages such as Python, Ruby, PowerShell, Java, and JavaScript
Network Security - Experience with network and system exploitation, including modern tactics, techniques, and procedures such as C2 frameworks, EDR bypass, privilege escalation, password cracking, and lateral movement
AI/LLM Security -Experience assessing non-deterministic security controls
Employment Sponsorship
This engagement is for independent contractors (1099) and is not eligible for any form of employment sponsorship. Applicants must be legally authorized to work in the United States without requiring visa sponsorship now or in the future. Applicants must be located in the United States
All new hires must pass a background check as a condition of employment