Senior Security Consultant (Web Application Penetration Tester)
Join the mission as a Senior Security Consultant. We are seeking a skilled and detail-oriented Penetration Tester to conduct thorough security assessments, identify vulnerabilities, and provide expert recommendations to strengthen our clients' security posture. As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices. Responsibilities:
- Conduct engagements on web applications and underlying APIs independently and provide technical oversight
- Review reports for accuracy in technical oversight, perform weekly QA oversight, and provide mentoring support to others
- Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture
- Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes
- Participate in development, implementation, and oversight of testing, delivery, and management strategies for key client accounts
- Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations.
Minimum Qualifications:
- Bachelor's degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience
- Minimum of 3-5 years of work experience in Penetration Testing
- Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus)
- Familiarity with offensive and defensive IT concepts and protocols
- Extensive understanding of the OWASP Top 10, MITRE ATT&CK framework, and various security frameworks.
- Working knowledge of Windows, Linux and MacOS operating systems internals
- Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
- Ability to work independently and as part of a team
- Proficient communication skills, both written and verbal
- Willingness to travel up to 5-10%
- This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs
Preferred Qualifications:
- Ability to provide technical and QA oversight on web applications and underlying APIs.
- Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)
- Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, GWAPT)