Work you'll do This role is responsible for providing penetration testing services through a combination of technology and manual ingenuity as part of the Global cyber services organization for member firms.
Responsibilities of this role include:
- Executing Penetration testing engagements:
- Web Application Penetration Testing
- Web Services / Application Programming Interface (API) Penetration Testing
- AI/LLM Penetration testing
- Network Penetration Testing
- Mobile Application Penetration Testing
- Thick Client Penetration Testing
- Providing consultative guidance to customers on findings identified in a clear and actionable fashion, both in writing and verbally
- Enhancing and updating testing methodologies, processes, and standards documentation
- Leveraging AI and LLM-based tools and prompt engineering, using both established platforms and emerging frameworks, to accelerate reconnaissance and generate or refine testing scripts
- Building, customizing, and maintaining AI-driven agents to automate recurring testing tasks
- Continuously validating the accuracy and reliability of self-developed AI tools, actively working to reduce hallucinations and false positives in vulnerability identification
- Evaluating and integrating emerging AI-assisted offensive security tooling into team methodology and playbooks
- Proficient at analyzing and understanding complex architecture designs.
- Ability to effectively communicate the services and capabilities our group can facilitate to our clients.
Professionals currently in a Deloitte Global role may be considered for this position, regardless of their US location.
QualificationsRequired: - Experienced with Kali Linux or other dedicated Penetration Testing OS Platform. With knowledge of common testing tools like Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and others
- Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities
- Familiarity with various AI models and frameworks from providers such as Anthropic and OpenAI, and experience configuring tools like Obsidian and Ollama is a plus for supporting other workflows.
- Working knowledge of one scripting language and familiarity with at least one software programming language and framework
- Demonstrated experience working with diverse stakeholders, preferably on a global multi-national basis
- Ability to manage concurrent initiatives and use effective judgment in prioritization and time management
- Strong written and verbal communication skills
- Must be a US Citizen
Preferred: - Certified Ethical Hacker (CEH) Certification
- Offensive Certified Security Professional (OSCP) Certification
- Any GIAC Certification (GSEC, GWAB, GPEN, GMOB, GCPN)
- OWASP Application Security Top 10
- OWASP API Security Top 10
- OWASP Thick Client Top 10
- OWASP LLM Top 10
- MITRE ATT&CK Framework
- Cloud Service testing
- Reverse Engineering
- Static Application Software Testing (SAST)
- Dynamic Application Testing (DAST)
- Experience of Agentic development and its application to support penetration testing
- Limited immigration sponsorship may be available.
Requisition code: 368417
Job ID 368417