Penetration Tester
Job
The Computer Merchant, Ltd.
Remote
$140,400 Salary, Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
82
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
Penetration Tester#26-00612
Menands, NY
40% Remote
Job Description
: Penetration Tester
JOB LOCATION
This is an onsite role in Albany, NY requiring two days per week, plus every other FridayWAGE RANGE
•: $65HR to $70HRJOB NUMBER:
26-00612 REQUIREDEXPERIENCE
Bachelor's degree in Computer Science, Information Security, or a related field. Minimum of 6 years of Development/Security experience Experience in Penetration Testing/Ethical Hacking with a focus on Java application security. Strong knowledge of Java programming and its security practices as well as scripting experience. Proficiency in web application security principles (e.g., OWASP). Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques. Experience with penetration testing tools like Burp Suite, Metasploit. Familiarity with Fortify on Demand SAST and DAST tools. Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).JOB DESCRIPTION
A Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats. Basic Minimum Experience. Bachelor's degree in a related software field with 6+ years in a Dev Sec role. Core Java coding experience. ious job background as an engineer and Dev Sec position on a large scale public enterprise scale application.Key Responsibilities:
Conduct penetration tests and vulnerability assessments for Java applications and infrastructure. Identify security flaws in Java code using automated and manual methods. Create and use custom exploits to test application security, simulating attacker tactics. Collaborate with Development teams to understand application architecture and find security weaknesses early. Collaborate with Testing teams to integrate with manual and automation testing. Provide guidance on secure coding and how to fix vulnerabilities. Stay updated on Java security threats and best practices. Help improve secure development processes (SDLC). Assist in responding to security incidents related to Java vulnerabilities, current publishedNIST CVE.
Clearly document and report findings, including technical details, risk assessment, and recommended solutions. Communicate findings and recommendations to both technical and non-technical staff. Contribute to security policies for Java development and deployment. Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses' browser tokens and cache manipulation and Production vs. none prod architecture. Familiar with MITRE Telecommunication&CK Framework.Qualifications:
Bachelor's degree in Computer Science, Information Security, or a related field. Minimum of 6 years of Development/Security experience Experience in Penetration Testing/Ethical Hacking with a focus on Java application security. Strong knowledge of Java programming and its security practices as well as scripting experience. Proficiency in web application security principles (e.g., OWASP). Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques. Experience with penetration testing tools like Burp Suite, Metasploit. Familiarity with Fortify on Demand SAST and DAST tools. Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS). Excellent problem-solving and analytical skills. Strong communication skills. High ethical standards and confidentiality.Preferred Qualifications:
Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications. Experience with scripting languages (e.g., Python, Bash). Experience with secure code review for Java. Familiarity with cloud security testing. Experience with mobile application penetration testing. Knowledge of regulations like HIPAA. Experience with API testing Equal opportunity employer as to all protected groups, including protected veterans and individuals with disabilities • While an hourly range is posted for this position, an eventual hourly rate is determined by a comprehensive salary analysis which considers multiple factors including but not limited to: job-related knowledge, skills and qualifications, education and experience as compared to others in the organization doing substantially similar work, if applicable, and market and business considerations. Benefits offered include medical, dental and vision benefits; dependent care flexible spending account; 401(k) plan; voluntary life/short term disability/whole life/term life/accident and critical illness coverage; employee assistance program; sick leave in accordance with regulation. Benefits may be subject to generally applicable eligibility, waiting period, contribution, and other requirements and conditions. Benefits offered are in accordance with applicable federal, state, and local laws and subject to change at TCM's discretion. #DiceSimilar remote jobs
BOI Payment Acceptance
Santa Ana, CA
Posted1 day ago
Updated2 hours ago
Similar jobs in Menands, NY
Trinity Health
Menands, NY
Posted4 days ago
Updated1 day ago
PYHIT (Peter Young Housing Industries & Treatment)
Menands, NY
Posted5 days ago
Updated1 day ago
Similar jobs in New York
Center Education Group
Cedarhurst, NY
Posted1 day ago
Updated2 hours ago
24 Seven Inc
New York, NY
Posted1 day ago
Updated2 hours ago
ACLU
New York, NY
Posted1 day ago
Updated2 hours ago