Rapid Strategy · 3 months ago
Senior Penetration Tester (WebApp and Network)
Rapid Strategy is an award-winning and African-American owned small business providing cybersecurity services to the private and public sector. They are seeking a Senior Penetration Test Consultant to simulate cyber attacks on web applications and identify security vulnerabilities. This role requires analytical skills, technical expertise, and creativity to effectively assess and improve cybersecurity measures.
AdviceCloud SecurityCyber SecuritySecurity
Responsibilities
Conducting thorough penetration tests on web applications to identify vulnerabilities
Utilizing various penetration testing tools and methodologies to simulate cyber attacks
Analyzing web applications for weaknesses and vulnerabilities using manual and automated methods
Understanding and exploiting known web vulnerabilities such as SQL injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and others
Preparing detailed reports on findings and providing recommendations for security improvements
Collaborating with development teams to advise on security best practices
Keeping abreast of the latest cybersecurity threats and testing methodologies
Qualification
Required
Bachelor's degree in Computer Science, Information Security, or a related field
5+ years of experience
Industry certifications such as Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), or GIAC Web Application Penetration Tester (GWAPT)
Strong understanding of web application technologies and protocols (HTTP/HTTPS, HTML, JavaScript, etc.)
Proficiency in using penetration testing tools like Burp Suite, OWASP ZAP, Metasploit, SQLMap, etc
Experience with known exploits and their mitigation
Ability to analyze and report on penetration testing outcomes effectively
Excellent problem-solving and analytical skills
Strong communication skills for collaboration with cross-functional teams
Preferred
Experience with programming/scripting languages such as Python, JavaScript, or Ruby
Knowledge of network security and operating systems
Familiarity with cloud environments and container technologies