Deloitte

Security Engineer III (Pen Tester)

Deloitte$100K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree required
  • 3+ years of hands-on experience in penetration testing
  • Proficiency with Burp Suite, Nmap, Metasploit, and scripting languages
  • Strong understanding of OWASP Top 10 and modern web app vulnerabilities
  • Ability to distinguish false positives from exploitable issues

Responsibilities

  • Partner with stakeholders to define testing objectives and success criteria
  • Perform active discovery of attack surfaces and map data flows
  • Conduct deep testing of web and mobile applications
  • Validate vulnerabilities and demonstrate impact safely
  • Identify weaknesses in network and infrastructure configurations
  • Evaluate blast radius and risk during post-exploitation analysis
  • Deliver clear reports with prioritized remediation steps

Benefits

  • Support for ongoing education and certifications
  • Opportunities for career advancement
  • Flexibility for remote work or hybrid arrangements
  • Access to cutting-edge tools and technology
  • Collaborative team culture focused on continuous improvement
Full Job Description
  • Engagement scoping & planning: Partner with stakeholders to define objectives, rules of engagement, in-scope assets, testing windows, and success criteria; ensure testing is authorized and safely executed.
  • Reconnaissance & enumeration: Perform passive and active discovery of attack surface, services, endpoints, APIs, and misconfigurations; map trust boundaries and data flows.
  • Manual application testing: Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws.
  • Vulnerability validation & exploitation: Safely verify findings and demonstrate impact (where permitted), including:
    • Cross-site scripting (XSS)
    • SQL injection (SQLi)
    • Cross-site request forgery (CSRF)
    • Server-side request forgery (SSRF)
    • Authentication and authorization flaws (e.g., broken access control, privilege escalation)
    • Session management issues, insecure deserialization, security misconfiguration, and business logic vulnerabilities
  • Network and infrastructure testing: Identify and validate weaknesses such as exposed services, weak segmentation, insecure protocols, credential issues, and misconfigurations across on-prem and cloud assets.
  • Post-exploitation analysis (when in scope): Assess blast radius, lateral movement paths, sensitive data exposure, and persistence risks; collect evidence responsibly and minimize operational impact.
  • Reporting & remediation support: Deliver clear reports including reproduction steps, risk ratings, evidence, and prioritized fixes; communicate effectively with both engineers and non-technical stakeholders; retest fixes as needed.
A successful candidate would possess these skills:
  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others
Qualifications

Required:
  • Bachelor's degree required.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
  • Must be able to obtain and maintain the required clearance for this role.
  • 3+ years of hands-on experience in penetration testing to include the following :
    • Strong understanding of web application security, OWASP Top 10, and modern attack techniques against web apps and APIs.
    • Proficiency with industry-standard tools such as Burp Suite, Nmap, Metasploit, and scripting for automation (e.g., Python/PowerShell/Bash), plus comfort writing lightweight proof-of-concepts.
    • Demonstrated ability to distinguish false positives vs. exploitable issues, document evidence, and provide pragmatic, developer-friendly remediation guidance.
    • Familiarity with common auth patterns (OAuth 2.0, OpenID Connect, SAML), API paradigms (REST/GraphQL), and modern app architectures (microservices, containers) is strongly preferred.
Preferred:
  • Certifications such as OSCP, OSWEP, CRTO, or eJPT (eLearnSecurity Junior Penetration Tester) are highly desirable.
  • 1+ years experience within the following:
    • Experience with mobile (Android/iOS) testing, cloud penetration testing (AWS/Azure/GCP), or CI/CD and supply chain testing.
    • Relevant certifications (examples: OSCP, GWAPT, GPEN, PNPT) or equivalent proven experience.
    • Proven experience with adversary simulation, adversary emulation, or red team operations.

About Deloitte

Deloitte is a multinational professional services network that provides audit, tax, consulting, enterprise risk and financial advisory services. The company was founded in London in 1845 and has since grown to become one of the largest professional services firms in the world. Deloitte has over 330,000 employees in more than 150 countries and territories. The company's mission is to help clients achieve their goals and make an impact that matters in their businesses and communities.
Learn more about Deloitte
Size
330,000 employees
Industry
Founded
1999

Similar Jobs

More Jobs at Deloitte

More Information Technology Jobs

Find similar Security Engineer III (Pen Tester) jobs: