Deloitte

Penetration Tester

Deloitte • $95K — $115K *
Tampa, FL 33647In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in penetration testing and vulnerability assessment.
  • Proficiency with Kali Linux and tools such as Burp Professional, Metasploit, and NMAP.
  • Familiarity with OWASP Top 10 vulnerabilities and various AI models.
  • Knowledge of at least one scripting language and basic programming.
  • Experience collaborating with global stakeholders across diverse teams.
  • Strong communication skills, both written and verbal.
  • U.S. Citizenship required.

Responsibilities

  • Execute various types of penetration tests including web applications, APIs, networks, and mobile apps.
  • Provide clear and actionable consultative guidance to clients based on test findings.
  • Enhance testing methodologies, processes, and standards documentations.
  • Leverage AI tools for reconnaissance and script generation.
  • Develop and maintain AI-driven agents to automate testing processes.
  • Validate the accuracy of self-developed AI tools to minimize false positives.
  • Integrate new AI-assisted security tools into team methodologies.

Benefits

  • Opportunity to work in a global cyber services organization.
  • Engagement in cutting-edge penetration testing across multiple platforms.
  • Access to ongoing training and development in AI and security technologies.
  • Collaborative environment with diverse teams worldwide.
  • Opportunity for professional certifications and career growth.
Full Job Description
Work you'll do

This role is responsible for providing penetration testing services through a combination of technology and manual ingenuity as part of the Global cyber services organization for member firms.

Responsibilities of this role include:
  • Executing Penetration testing engagements:
    • Web Application Penetration Testing
    • Web Services / Application Programming Interface (API) Penetration Testing
    • AI/LLM Penetration testing
    • Network Penetration Testing
    • Mobile Application Penetration Testing
    • Thick Client Penetration Testing
  • Providing consultative guidance to customers on findings identified in a clear and actionable fashion, both in writing and verbally
  • Enhancing and updating testing methodologies, processes, and standards documentation
  • Leveraging AI and LLM-based tools and prompt engineering, using both established platforms and emerging frameworks, to accelerate reconnaissance and generate or refine testing scripts
  • Building, customizing, and maintaining AI-driven agents to automate recurring testing tasks
  • Continuously validating the accuracy and reliability of self-developed AI tools, actively working to reduce hallucinations and false positives in vulnerability identification
  • Evaluating and integrating emerging AI-assisted offensive security tooling into team methodology and playbooks
  • Proficient at analyzing and understanding complex architecture designs.
  • Ability to effectively communicate the services and capabilities our group can facilitate to our clients.
Professionals currently in a Deloitte Global role may be considered for this position, regardless of their US location.

Qualifications

Required:
  • Experienced with Kali Linux or other dedicated Penetration Testing OS Platform. With knowledge of common testing tools like Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and others
  • Familiarity with OWASP Top 10 software security weaknesses and vulnerabilities
  • Familiarity with various AI models and frameworks from providers such as Anthropic and OpenAI, and experience configuring tools like Obsidian and Ollama is a plus for supporting other workflows.
  • Working knowledge of one scripting language and familiarity with at least one software programming language and framework
  • Demonstrated experience working with diverse stakeholders, preferably on a global multi-national basis
  • Ability to manage concurrent initiatives and use effective judgment in prioritization and time management
  • Strong written and verbal communication skills
  • Must be a US Citizen
Preferred:
  • Certified Ethical Hacker (CEH) Certification
  • Offensive Certified Security Professional (OSCP) Certification
  • Any GIAC Certification (GSEC, GWAB, GPEN, GMOB, GCPN)
  • OWASP Application Security Top 10
  • OWASP API Security Top 10
  • OWASP Thick Client Top 10
  • OWASP LLM Top 10
  • MITRE ATT&CK Framework
  • Cloud Service testing
  • Reverse Engineering
  • Static Application Software Testing (SAST)
  • Dynamic Application Testing (DAST)
  • Experience of Agentic development and its application to support penetration testing
  • Limited immigration sponsorship may be available.

    Requisition code: 368417

    Job ID 368417

About Deloitte

Deloitte is a multinational professional services network that provides audit, tax, consulting, enterprise risk and financial advisory services. The company was founded in London in 1845 and has since grown to become one of the largest professional services firms in the world. Deloitte has over 330,000 employees in more than 150 countries and territories. The company's mission is to help clients achieve their goals and make an impact that matters in their businesses and communities.
Learn more about Deloitte
Size
330,000 employees
Industry
Founded
1999

Similar Jobs

More Jobs at Deloitte

More Information Technology Jobs

Find similar Penetration Tester jobs: