Long term contract consulting opportunity for an experience Penetration Test. Client Requirements:
Must be W2 hourly (no C2C)
Work authorization requirements: US Citizen or GC holder
Seeking an experienced Penetration Tester to identify, assess, and validate security vulnerabilities across web applications, APIs, and enterprise systems. This role will lead end-to-end penetration testing engagements, partner closely with engineering teams to remediate findings, and help strengthen the organization's overall security posture through proactive testing and risk assessments.
Key Responsibilities
Conduct end-to-end penetration testing engagements, including scoping, exploitation, validation, and reporting.
Perform security assessments of web applications and APIs, identifying vulnerabilities and recommending effective remediation strategies.
Utilize industry-standard security testing tools such as Burp Suite, Nmap, and exploitation frameworks to identify security risks.
Develop Python or Go scripts to automate testing activities and improve penetration testing workflows.
Document vulnerabilities clearly and provide actionable remediation guidance for engineering teams.
Collaborate with development and engineering teams to validate fixes and verify vulnerability remediation.
Support secure development initiatives by identifying risks early and contributing to threat modeling activities.
Assist with PCI-related penetration testing and compliance efforts as needed.
Contribute to bug bounty programs by validating, triaging, and escalating reported vulnerabilities.
Continuously evaluate and improve penetration testing methodologies, tools, and processes.
Mentor junior team members and provide technical guidance on penetration testing best practices.
Required Qualifications
7+ years of cybersecurity experience with increasing responsibility in penetration testing.
5+ years of hands-on penetration testing experience focused on web applications and APIs within enterprise environments.
Strong knowledge of web application security vulnerabilities, including OWASP Top 10, authentication and authorization flaws, and injection attacks.
Advanced proficiency with Burp Suite, Nmap, and common exploitation frameworks.
Experience developing automation or testing scripts using Python or Go.
Strong analytical, communication, and documentation skills with the ability to deliver clear, actionable security findings.
Proven experience collaborating with engineering teams to validate and remediate vulnerabilities.
Preferred Qualifications
Experience testing mobile applications, embedded systems, hardware, or third-party/vendor platforms.
Familiarity with PCI penetration testing requirements and regulatory compliance.
Experience supporting or managing bug bounty programs.
Knowledge of threat modeling and identifying security risks during application design and development.
ITR Group offers a competitive compensation and benefits package, including medical, dental, and 401(k) for eligible employees. The W2 pay range for this type of role is approximately $74.00 - $97.00 per billable hour. This range is an estimate and not a guarantee of compensation. The final rate will be determined by factors such as experience, market trends, and specific job assignments. Discover more about how ITR Group connects top talent with leading client opportunities.
ITR Group is an Equal Opportunity Employer. We do not discriminate against applicants on the basis of their race, color, national origin, religion, creed, disability, age, sex, sexual orientation, gender identity, marital status, familial status, or status with regard to public assistance, or membership or activity in a local human rights commission.
No applications from candidates residing in California or New York
Numbers & Facts
Location
Brooklyn Park, MN (Remote)
Salary
$74–$97 Per Hour
Skills
Analysis Skillsunmatched
Application Programming Interface (API)unmatched
Applications Securityunmatched
Best Practicesunmatched
Bug Tracking/Defect Managementunmatched
Communication Skillsunmatched
Computer Securityunmatched
Continuous Improvementunmatched
Documentationunmatched
Industry Standardsunmatched
Internet Applicationunmatched
Internet Securityunmatched
Market Trend Analysisunmatched
Mentoringunmatched
NMapunmatched
PCIunmatched
Penetration Testingunmatched
Python Programming/Scripting Languageunmatched
Quality Assurance Methodologyunmatched
Regulatory Complianceunmatched
Risk Analysisunmatched
Security Analysisunmatched
Software Designunmatched
Software Developmentunmatched
Technical Leadershipunmatched
Test Automationunmatched
Test Requirementsunmatched
Test Scriptsunmatched
Test Toolsunmatched
Testingunmatched
Threat Modelingunmatched
United States Citizenunmatched
Web Analyticsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.