Web Application Tester Job at Clearance Jobs, Alexandria, VA

WCtFU0JrY1NHUmNDM21obW9MWHVtNUtTOFE9PQ==
  • Clearance Jobs
  • Alexandria, VA

Job Description

Web Application Penetration Tester

As a Web Application Penetration Tester joining our team, you will play a pivotal role in ensuring our customers' applications and underlying data are secure. Your expertise will enhance the support we provide to a wide variety of entities, including commercial enterprises and government organizations. Join us and be at the forefront of securing the data our customers rely on, while enjoying a dynamic and collaborative work culture that values innovation, growth, and teamwork.

Responsibilities: This position operates with minimal government lead supervision supporting the Department of Defense. Our company also has a commercial assessment practice that occasionally utilizes DoD-based team members for additional assessment support:

  • Evaluating a variety of deployed web applications to identify security issues that may affect data availability, reliability, and confidentiality, such as but not limited to the OWASP Top 10
  • Collaborate with customers to understand the intended flow of deployed web applications and evaluate these applications for potential flaws, such as errors in business logic, authentication and authorization flaws, input validation weaknesses, session management vulnerabilities, and other security misconfigurations that could allow deviations from the intended functionality
  • Identify and analyze potential attack chains by evaluating how individual vulnerabilities can be combined to exploit the application, and provide comprehensive mitigation strategies
  • When using automated scanning tools, manually confirm identified or tentative issues, and ensure that the coverage provided by these tools meets the customers' expectations
  • Periodically review public posts regarding vulnerabilities without a public proof-of-concept (PoC) that may be applicable to a target web application or application server. Attempt to reverse engineer these vulnerabilities and develop a working PoC, as applicable to web assets in the client's environment
  • Utilize source code or binaries, when provided or open source, to focus and prioritize testing efforts. This includes familiarity with static code analysis to identify potential vulnerabilities, understanding the application's architecture, pinpointing critical components and functions, and tailoring penetration testing strategies to efficiently uncover security flaws in the most impactful areas.
  • Support customers by providing guidance on temporary mitigations and permanent remediations. This includes contributing to detailed written reports, offering remote support when necessary, and effectively communicating technical findings to a less technical audience to ensure understanding and proper implementation of security measures.
  • Less frequently, as business needs require, assist with basic network penetration testing tasks, contributing to a broader understanding of the organization's security posture and supporting the overall security assessment process
  • This position requires a hybrid onsite work schedule and occasional travel to other locations.

Requirements:

  • Bachelor's degree and 5+ years recent experience in offensive cyber security targeting web applications required; having prior experience elsewhere in information technology or cyber security fields is a plus. Education can be substituted by solid experience in the field.
  • Active DoD 8570 IAT Level I or greater and at least one of the following certifications in good standing: OSWA, GWAPT, GXPN, GPEN, OSCP, OSWE
  • Active DoD Top Secret clearance
  • An understanding of common web application vulnerabilities and a willingness to learn as new vulnerabilities are discovered and documented
  • Ability to communicate effectively, while conveying highly technical concepts to both technical and nontechnical stakeholders
  • Familiarity with at least one common web-related programming language
  • Familiarity with working under both Windows and at least one *nix-like OS; having a common certification demonstrating familiarity with administering an OS is a plus
  • Proficiency in using a variety of penetration testing tools, including but not limited to Burp Suite, OWASP ZAP, Metasploit, Nessus, Nmap, and various automated web application scanning tools.
  • Coding/Scripting experience a plus

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy), national origin, disability, veteran status, age, genetic information, or other legally protected status.

Clearance Jobs

Job Tags

Permanent employment, Temporary work, Remote work,

Similar Jobs

Schneider

CDL-A - Dedicated nighttime truck driver - Target Job at Schneider

 ...420 weekly Home time: Weekly Experience: 3 months or greater CDL experience Overview ~ Haul retail...  .... Weekly performance pay. Paid orientation. Paid time off after...  ...Class A driving experience. Need CDL training? Explore our company-paid CDL... 

Planet Healthcare

Travel Paramedic Job at Planet Healthcare

 ...Job Description Planet Healthcare is seeking a travel Paramedic for a travel job in Portage, Wisconsin. Job Description & Requirements ~ Specialty: Paramedic ~ Discipline: Allied Health Professional ~ Start Date: 10/27/2025~ Duration: 13 weeks ~48 hours... 

BlackRock Resources LLC

Senior Financial Controller Job at BlackRock Resources LLC

Senior Financial Controller We are seeking an experienced Senior Financial Controller with 7- 10+ years of expertise in financial management, emphasizing advanced proficiency in NetSuite ERP software. This role will oversee all accounting and financial functions for...

PRIDE Health

Travel Discharge Planner RN - $2,295 per week Job at PRIDE Health

 ...employees comprehensive healthcare coverage (medical, dental, and vision plans), supplemental coverage (accident insurance, critical illness insurance and hospital indemnity), 401(k)-retirement savings, life & disability insurance, an employee assistance program, legal... 

Unilever

Processing Associate/Mixer Job at Unilever

Process Associate/Mixer Location of Job: Independence MO (Union)2nd Shift: 3:00 pm - 11:30 pm (Mon- Fri)3rd Shift: 11:00 pm - 7:30 am (Sun- Thurs) Pay Rate $24.17 with an additional $0.50 - $0.75 shift differential | Weekly pay periods Benefit Overview ...