Sr. Web Application Penetration Tester - Cybersecurity

Remote Full-time
Position: Sr. Web Application Penetration Tester - Cybersecurity Location: Remote Hiring Mode: 12 Months Contract Job Description: The Senior Web Application Penetration Tester is responsible for identifying security vulnerabilities in internally developed and third-party web applications used across the Utility. This role focuses exclusively on application-layer security testing, helping ensure that customer-facing and internal web applications are resilient against real-world threats. The position works closely with application development, cloud, and security teams to reduce risk and improve secure development practices. Key Responsibilities: Web Application & API Penetration Testing • Conduct manual and automated penetration testing of web applications and RESTful APIs • Identify and exploit common and advanced web vulnerabilities (e.g., OWASP Top 10, business logic flaws) • Test authentication, authorization, session management, and access controls • Perform API security testing including authorization bypass, mass assignment, and input validation flaws • Assess application security across development, test, and production environments (as authorized) Secure SDLC & Collaboration • Partner with application development and DevSecOps teams to integrate security testing into the SDLC • Provide guidance on secure coding practices and vulnerability remediation • Support threat modeling and design reviews for new or enhanced applications Reporting & Risk Communication • Produce detailed penetration test reports with clear reproduction steps and remediation recommendations • Communicate risk in business-appropriate language for technical and non-technical stakeholders • Validate remediation through follow-up testing and re-assessments Tools & Techniques • Use industry-standard tools such as Burp Suite, OWASP ZAP, Postman, and custom scripts • Leverage manual testing techniques to identify business logic and workflow vulnerabilities • Stay current on emerging web application attack techniques and defenses Required Qualifications • 6+ years of cybersecurity experience with a strong focus on web application penetration testing • Demonstrated experience testing modern web applications and APIs • Strong understanding of HTTP/S, REST, JSON, authentication mechanisms, and web architectures • Proficiency with tools such as Burp Suite Pro and API testing tools • Working knowledge of at least one scripting or programming language (e.g., Python, JavaScript, or PowerShell) • Strong written and verbal communication skills Preferred Qualifications • Experience testing customer-facing applications in regulated environments • Familiarity with cloud-hosted applications and CI/CD pipelines • Knowledge of OWASP ASVS, SAMM, or similar application security standards • Certifications such as OSCP, GWAPT, OSWE, or similar Apply tot his job
Apply Now →

Similar Jobs

Experienced Overnight Customer Care and Technical Support Advisor – Remote Work Opportunity with arenaflex

Remote Full-time

Experienced Remote Customer Support Specialist – Live Chat and Client Service Expert for arenaflex

Remote Full-time

Experienced Customer Service Professional - Self Storage Manager for a Dynamic and Industry-Leading Team

Remote Full-time

Senior Director II, Customer Strategic Insights and Innovation Leader for arenaflex Foodservice and On-Premise Business Growth

Remote Full-time

Experienced Part-Time Remote Customer Service Representative – Flexible Hours and Work from Home Opportunity

Remote Full-time

Experienced Customer Service Advisor for Remote Work Opportunities – Delivering Exceptional Support and Service Excellence at arenaflex

Remote Full-time

Experienced Customer Service and Data Entry Representative for Claims Coordination Team - 100% Remote Opportunity with arenaflex

Remote Full-time

Experienced Healthcare Customer Service Representative – Remote Work Opportunity with arenaflex

Remote Full-time

Experienced Entry Level Remote Customer Service Representative – Delivering Exceptional Support and Driving Customer Satisfaction at arenaflex

Remote Full-time

Experienced Data Entry Specialist – Remote Opportunity for Detail-Oriented Professionals to Drive Business Excellence at arenaflex

Remote Full-time

Solution Architect (Remote, Eastern or Central Time Zone)

Remote Full-time

Facilities Manager (Midwest Region)

Remote Full-time

Experienced Product Manager - Customer Loyalty and Engagement - Driving Business Growth through Innovative Product Development and Strategic Planning

Remote Full-time

Experienced Customer Service Representative for National Campaigns Unit – Fully Remote Opportunity with arenaflex

Remote Full-time

[Remote] Staff DFIR Investigator

Remote Full-time

**Flexible Remote Customer Service Representative – Deliver Exceptional Experiences for arenaflex Clients**

Remote Full-time

New Jersey - Social Content Creator for Family Activity Website (Remote-NJ Area)

Remote Full-time

Director, Artificial Intelligence (AI) Compliance

Remote Full-time

Quality Improvement Spec - Infection Prevention (Remote)

Remote Full-time

Part Time Adjunct Faculty - Nursing

Remote Full-time
← Back to Home