Logo
Kaizen Lab Inc.

Senior Web Application Penetration Tester (Charlotte, NC) Featured Charlotte, NC

Kaizen Lab Inc., Charlotte, North Carolina, United States, 28245


Location:

Charlotte, NCJob Description:We are seeking a highly skilled and experienced Senior Web Application Penetration Tester to join our dynamic team in Charlotte, NC office. As a Senior Penetration Tester, you will be responsible for identifying and exploiting vulnerabilities in web applications, conducting thorough security assessments, and providing actionable recommendations to enhance our clients' security posture.Key Responsibilities:Conduct comprehensive penetration tests on web applications to identify security vulnerabilities, including but not limited to injection flaws, authentication and session management weaknesses, cross-site scripting (XSS), and insecure direct object references.Utilize both manual and automated techniques to discover, exploit, and mitigate security vulnerabilities.Collaborate with cross-functional teams to prioritize and remediate identified vulnerabilities based on risk assessment.Develop detailed reports documenting findings, including clear and actionable recommendations for remediation.Stay up-to-date with the latest cybersecurity threats, vulnerabilities, and mitigation techniques, and actively contribute to the team's knowledge base.Provide mentorship and guidance to junior team members, fostering their professional development in the field of web application security.Act as a subject matter expert in web application security, providing guidance and support to both technical and non-technical stakeholders.Requirements:Bachelor's degree in Computer Science, Information Security, or related field. Equivalent work experience may be considered.Minimum of 5 years of experience in web application penetration testing.Proficiency in using industry-standard penetration testing tools such as Burp Suite, OWASP ZAP, and Metasploit.Extensive knowledge of web application security vulnerabilities and exploitation techniques, including OWASP Top 10.Experience with various operating systems, including Windows, Linux, and Unix.Excellent communication skills, with the ability to effectively convey technical information to both technical and non-technical stakeholders.One or more relevant certifications such as:Offensive Security Certified Professional (OSCP)Certified Information Systems Security Professional (CISSP)Certified Ethical Hacker (CEH)EC-Council Certified Security Analyst (ECSA)Must be a US Citizen.Preferred Qualifications:Experience with cloud platforms such as AWS, Azure, or Google Cloud Platform.Familiarity with DevOps principles and practices.Experience with mobile application security testing.Knowledge of secure coding practices and static code analysis tools.

#J-18808-Ljbffr