Ethical Hacker

Ova Technologies

$90K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience).
  • 2-5 years of experience in ethical hacking or penetration testing.
  • Strong understanding of networking concepts and protocols.
  • Hands-on experience with web application security testing and OWASP vulnerabilities.
  • Proficiency with Linux-based security environments like Kali Linux.
  • Experience with penetration testing tools and vulnerability assessment tools.
  • Knowledge of scripting languages such as Python, Bash, or PowerShell.

Responsibilities

  • Conduct penetration testing across web and mobile applications, APIs, networks, and infrastructure.
  • Identify and document security vulnerabilities using ethical hacking techniques.
  • Perform vulnerability assessments and security reviews.
  • Align security testing with industry frameworks like OWASP and NIST.
  • Execute web application security tests focusing on authentication and injection vulnerabilities.
  • Analyze findings and prepare detailed reports with remediation recommendations.
  • Collaborate with teams to validate fixes and strengthen security controls.

Benefits

  • Competitive salary and performance-based incentives.
  • Comprehensive health and wellness benefits.
  • Flexible or hybrid work arrangements.
  • Support for cybersecurity training, certification, and conferences.
  • Opportunity to tackle real-world cybersecurity challenges.
  • Collaborative work environment focused on continuous improvement.
Full Job Description
Ethical Hacker

Job Title

Ethical Hacker / Penetration Tester

Job Summary

We are seeking a skilled Ethical Hacker to identify, analyze, and help remediate security vulnerabilities across applications, networks, systems, and cloud environments. The ideal candidate will perform authorized security assessments, penetration testing, vulnerability analysis, and security research to strengthen organizational defenses. You will collaborate with security engineers, developers, infrastructure teams, and compliance professionals to improve overall cybersecurity posture.

Key Responsibilities
  • Conduct authorized penetration testing across web applications, mobile applications, APIs, networks, cloud environments, and infrastructure.
  • Identify, exploit, validate, and document security vulnerabilities using ethical hacking methodologies.
  • Perform vulnerability assessments, security reviews, and risk analysis.
  • Execute security testing aligned with industry frameworks such as OWASP, PTES, and NIST guidelines.
  • Conduct web application security testing including authentication, authorization, injection, session management, and business logic testing.
  • Perform network security assessments, including configuration reviews and vulnerability analysis.
  • Analyze security findings and prepare detailed reports with risk ratings and remediation recommendations.
  • Collaborate with developers, system administrators, and security teams to validate fixes and improve security controls.
  • Conduct threat research and stay updated on emerging vulnerabilities, exploits, and attack techniques.
  • Support red team exercises, security audits, and incident response investigations when required.
  • Maintain documentation of testing methodologies, findings, and security improvements.

Required Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field (or equivalent practical experience).
  • 2-5 years of experience in ethical hacking, penetration testing, vulnerability assessment, or security engineering.
  • Strong understanding of networking concepts, TCP/IP, DNS, HTTP/HTTPS, VPNs, and firewalls.
  • Hands-on experience with web application security testing and OWASP Top 10 vulnerabilities.
  • Proficiency with Linux-based security environments such as Kali Linux or Parrot OS.
  • Experience using penetration testing and vulnerability assessment tools.
  • Knowledge of scripting languages such as Python, Bash, or PowerShell.
  • Strong understanding of security principles, authentication mechanisms, encryption, and access controls.

Preferred Qualifications
  • Experience performing penetration tests for web applications, APIs, mobile applications, and cloud platforms.
  • Knowledge of cloud security testing for AWS, Azure, or Google Cloud environments.
  • Familiarity with Active Directory security assessments and enterprise network testing.
  • Experience with vulnerability management platforms and security reporting tools.
  • Understanding of malware analysis, exploit development, or reverse engineering concepts.
  • Experience with bug bounty programs or responsible vulnerability disclosure.
  • Knowledge of DevSecOps and application security practices.

Technical Skills
  • Kali Linux
  • Burp Suite
  • Metasploit Framework
  • Nmap
  • Wireshark
  • Nessus
  • OpenVAS
  • OWASP ZAP
  • SQLMap
  • Nikto
  • Gobuster
  • Hydra
  • Python
  • Bash
  • PowerShell
  • Git
  • Linux
  • Windows Security
  • Web Application Security
  • API Security
  • Cloud Security

Soft Skills
  • Strong analytical and investigative skills.
  • Excellent problem-solving abilities.
  • Clear technical writing and reporting skills.
  • Ability to communicate security risks to technical and non-technical stakeholders.
  • Strong attention to detail and ethical judgment.
  • Curiosity and passion for cybersecurity research and continuous learning.

Nice to Have
  • Experience with red team operations, adversary simulation, or threat emulation.
  • Knowledge of Active Directory attacks and defenses.
  • Familiarity with container and Kubernetes security testing.
  • Experience with AI security, LLM application security, or prompt injection testing.
  • Contributions to security research, vulnerability disclosures, or cybersecurity communities.
  • Professional certifications such as OSCP, CEH, PNPT, GPEN, GWAPT, CISSP, or Security+.

Benefits
  • Competitive salary and performance-based incentives.
  • Comprehensive health and wellness benefits.
  • Flexible or hybrid work arrangements.
  • Cybersecurity training, certification, and conference support.
  • Opportunity to work on advanced security assessments and real-world cybersecurity challenges.
  • Collaborative environment focused on continuous security improvement.

Similar Jobs

  • Offensive Security Engineer
    $73K — $171K *
    Central Hudson Gas & Electric Corp.
    Poughkeepsie, NY 12601 (Dutchess County)
  • Application Penetration Tester
    $62K — $141K *
    Booz Allen Hamilton, Inc.
    Chantilly, VA 20152 (Loudoun County)
  • GovCIO
    Senior Penetration Tester
    $124K — $180K *
    GovCIO
    Washington, DC 20032 (District Of Columbia County)
  • State Street Corporation
    Red Team Engineer
    $125K — $215K *
    State Street Corporation
    Princeton, NJ 08540 (Mercer County)
  • State Street Corporation
    Red Team Engineer
    $125K — $215K *
    State Street Corporation
    Quincy, MA 02169 (Norfolk County)
  • State Street Corporation
    Red Team Engineer
    $125K — $215K *
    State Street Corporation
    Clifton, NJ 07011 (Passaic County)

More Jobs at Ova Technologies

  • Digital Forensics Specialist
    $80K — $120K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Release Engineer
    $90K — $130K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Ethical Hacker
    $90K — $130K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • MLOps Engineer
    $120K — $150K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • MLOps Engineer
    $100K — $150K *
    Remote
    Enterprise Technology
    Remote in New York, NY

More Information Technology Jobs

Find similar Ethical Hacker jobs: