Application Security Pentester, Specialist

$90K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Minimum five years of related work experience, with three years in IT security or application development.
  • Undergraduate degree in a related field or equivalent combination of training and experience.
  • Hands-on experience with web application, API, and network penetration testing.
  • Experience with Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tooling preferred.
  • Background in cloud and mobile penetration testing or AI red teaming is a plus.
  • Proficiency in at least one programming or scripting language, such as Python or Java.
  • Preferred security certifications include OSCP, OSWA, OSWE, GPEN, or GWAPT.

Responsibilities

  • Leads penetration tests across various technologies, including web apps, APIs, and AI systems.
  • Performs manual and automated vulnerability testing.
  • Conducts Secure Code Reviews and Dynamic Application Security Testing (DAST) as needed.
  • Develops detailed assessment reports and presents findings to stakeholders.
  • Collaborates with IT and business units for risk assessment and management.
  • Contributes to evolving team processes, methodologies, and best practices.
  • Maintains expertise in vulnerability classes and emerging security threats.

Benefits

  • Collaborative work environment with IT and business stakeholders.
  • Opportunity to enhance technical skills and stay updated on security trends.
  • Involvement in diverse penetration testing across various technologies.
  • Access to training and professional development resources.
  • Engagement in special projects for skill diversification.
Full Job Description

Leads and executes security assessments to identify, validate, and communicate security risks. Performs manual and automated penetration testing, conducts additional security assessments such as Secure Code Reviews and Dynamic Application Security Testing (DAST), and produces clear, actional reports for technical teams and leadership. Partners with IT and business stakeholders to assess risk, support remediation, and improve the organization’s overall security posture.

Core Responsibilities

  • Leads and executes penetration tests across a variety of technologies, including web applications, APIs, and AI-enabled systems. Performs manual and automated testing to identify, exploit, and validate vulnerabilities.

  • Conducts other security assessments as needed, including Secure Code Reviews and/or Dynamic Application Security Testing (DAST).

  • Develops detailed assessment reports and presents findings to technical teams and leadership. Coordinates security risk reporting and collaborates with IT sub-divisions, third-party partners, and business units to identify the impact of technology implementations on IT and business operations.

  • Contributes to the evolution of team processes, testing methodologies, standards, and best practices.

  • Maintains subject-matter expertise in common vulnerability classes and attack techniques (e.g., OWASP Top 10, OWASP Top 10 API, SANS Top 25), and remains familiar with relevant security frameworks (e.g., MITRE ATT&CK). Stays current on emerging threats, tools, and offensive security techniques.

  • Participates in special projects and performs other duties as assigned.

Qualifications

  • Minimum five years related work experience with three years experience in IT security or application development.

  • Undergraduate degree in related field or equivalent combination of training and experience.

  • Hands-on experience performing web application, API, and network penetration testing.

  • Preferred experience with Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tooling.

  • Experience in on or more of the following a plus:  cloud penetration testing, mobile penetration testing, AI red teaming

  • Proficiency in at least one programming or scripting language (e.g., Python, Java).

  • Preferred security certifications such as OffSec Certified Professional (OSCP), OffSec Web Assessor (OSWA), OffSec Web Expert (OSWE), GIAC Penetration Tester (GPEN), or GIAC Web Application Penetration Tester (GWAPT).

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

Similar Jobs

More Jobs at

More Information Technology Jobs

Find similar Application Security Pentester, Specialist jobs: