Senior Web Application Penetration Tester

SixGen, Inc.

$100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in web application penetration testing or offensive cybersecurity.
  • Hands-on experience with manual web application security assessments.
  • In-depth knowledge of modern web app vulnerabilities and exploitation techniques.
  • Proficient in network mapping, vulnerability scanning, and testing methodologies.
  • Familiar with NIST 800-series standards and cybersecurity norms.
  • Experience in developing scripts or custom testing tools.
  • Strong analytical, problem-solving, and communication abilities.

Responsibilities

  • Conduct penetration testing of web applications, APIs, mobile applications, databases, and client-side technologies.
  • Perform application enumeration, endpoint discovery, and exploitation activities.
  • Identify, validate, and assess vulnerabilities in complex environments.
  • Analyze attack paths to determine business and operational impacts.
  • Develop and utilize custom tools and scripts for enhanced testing.
  • Research emerging vulnerabilities and attack techniques.
  • Collaborate with clients to review findings and recommend remediation.

Benefits

  • Employer-paid health insurance for you and your family.
  • Employer-paid short/long term disability and basic life insurance.
  • 401K with a 4% employer contribution.
  • Professional development reimbursement for training and certifications.
  • Flexible and remote work policies.
  • Flexible PTO and holiday schedules.
Full Job Description
POSITION OVERVIEW

Position: Senior Web Application Penetration Tester
Job Type: Full-time
Location: Maryland, Northern Virginia, or Remote
Clearance Requirements: Must be able to obtain a Secret Clearance
Travel Requirements: Up to 10%
Experience: 5+ years
WHAT YOU'LL DO

We are seeking a skilled and motivated Senior Web Application Penetration Tester to join our growing cyber operations team. The ideal candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques, with the ability to identify complex attack paths and develop creative solutions to challenging security problems.

This role goes far beyond automated scanning. Successful candidates will conduct in-depth assessments of web applications, APIs, mobile applications, and supporting infrastructure while leveraging custom tooling, manual testing techniques, and advanced exploitation methodologies to uncover impactful security findings.
KEY RESPONSIBILITIES
Web Application Security Assessments
  • Conduct penetration testing of web applications, APIs, mobile applications, databases, and client-side technologies.
  • Perform application enumeration, endpoint discovery, vulnerability research, and exploitation activities.
  • Identify, validate, and assess vulnerabilities across complex environments.
  • Analyze attack paths and security weaknesses to determine business and operational impact.
Technical Analysis & Research
  • Develop and utilize custom tools, scripts, and payloads to support testing activities.
  • Perform network mapping, vulnerability analysis, and security assessments across applications and supporting infrastructure.
  • Research emerging vulnerabilities, attack techniques, and exploitation methodologies.
  • Support post-exploitation activities involving cloud and enterprise environments when applicable.
Client Engagement & Reporting
  • Collaborate with clients and internal teams to define scope, review findings, and recommend remediation strategies.
  • Communicate technical concepts and findings to both technical and non-technical stakeholders.
  • Produce comprehensive reports, including detailed findings, exploitation procedures, risk analysis, and mitigation recommendations.
  • Participate in client meetings and provide ongoing updates throughout assessment activities.
QUALIFICATIONS
  • 5+ years of experience in web application penetration testing or offensive cybersecurity.
  • Demonstrated experience conducting manual web application security assessments.
  • Knowledge of modern web application vulnerabilities, attack methodologies, and exploitation techniques.
  • Experience with network mapping, vulnerability scanning, and penetration testing methodologies.
  • Familiarity with NIST 800-series standards and cybersecurity best practices.
  • Experience developing scripts, payloads, or custom testing tools.
  • Strong analytical, problem-solving, and communication skills.
Preferred Certifications

One or more of the following certifications is strongly preferred:
  • OSCP (Preferred)
  • OSWA
  • OSWE
  • CRTO
  • CBBH
  • GWAPT
  • Other relevant hands-on offensive security certifications
PREFERRED QUALIFICATIONS
  • Experience with cloud environments and post-exploitation activities.
  • Experience with Active Directory security assessments.
  • Familiarity with FISMA compliance requirements.
  • Experience supporting government or regulated industry clients.
  • Proficiency with common offensive security tools and frameworks.
COMPENSATION & BENEFITS

At SIXGEN, we are committed to fair and equitable compensation practices. Compensation for this role will be based on experience, qualifications, technical expertise, and overall alignment with the position.

Additionally, SIXGEN offers top-tier benefits for full-time employees, including:
  • Employer-paid health insurance premiums (medical, dental, vision) for you and your family
  • Employer-paid short/long term disability insurance and basic life/AD&D insurance
  • 401K with a 4% employer contribution
  • Professional development reimbursement options available (training, certification, education, etc)
  • Flexible and remote work policies for most positions
  • Flexible PTO and holiday schedule

For more information, please reach out to our Director of Human Resources, Amy Maxwell at [redacted].

Similar Jobs

More Jobs at SixGen, Inc.

More Information Technology Jobs

Find similar Senior Web Application Penetration Tester jobs: