• Albany, NY
  • Instant Apply
8 days ago

Job Description

Job Profile:
Ethical Hacker/Penetration Tester Principal

Job Qualifications:

Skills:
Application Security, Secure Coding, Security Testing

Experience:
6 + years of related experience

Job Description:

This role requires travel to Albany, NY twice a month.

Job Brief:
A Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats.

Basic Minimum Experience.
  • Bachelor's degree in a related software field with 6+ years in a Dev Sec role.
  • Core Java coding experience.
  • Previous job background as an engineer and Dev Sec position on a large-scale public enterprise scale application.

Key Responsibilities:
  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Collaborate with Development teams to understand application architecture and find security weaknesses early.
  • Collaborate with Testing teams to integrate with manual and automation testing.
  • Provide guidance on secure coding and how to fix vulnerabilities.
  • Stay updated on Java security threats and best practices.
  • Help improve secure development processes (SDLC).
  • Assist in responding to security incidents related to Java vulnerabilities, current published NIST CVE.
  • Clearly document and report findings, including technical details, risk assessment, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Contribute to security policies for Java development and deployment.
  • Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses' browser tokens and cache manipulation and Production vs. none prod architecture.
  • Familiar with MITRE Telecommunication&CK Framework.

Qualifications:
  • Bachelor's degree in computer science, Information Security, or a related field.
  • Minimum of 6 years of Development/Security experience
  • Experience in Penetration Testing/Ethical Hacking with a focus on Java application security.
  • Strong knowledge of Java programming and its security practices as well as scripting experience.
  • Proficiency in web application security principles (e.g., OWASP).
  • Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques.
  • Experience with penetration testing tools like Burp Suite, Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
  • Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.

Preferred Qualifications:
  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.
  • Experience with scripting languages (e.g., Python, Bash).
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations like HIPAA.
  • Experience with API testing

Telecommuting Options:
Hybrid


GC and Citizen only


All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Numbers & Facts

LocationAlbany, NY
IndustryComputer/IT Services
Company Size100 to 499 employees
Year Founded1997
Websitehttps://www.tscti.com/careers-0

About Company

22nd Century Technologies, Inc., is one of the fastest growing IT Service Integrator and Workforce Solution companies in the United States. Founded in 1997, 22nd Century Technologies is a Certified National Minority Business Enterprise with 6,000+ people including 600+ Cyber SMEs nationwide supporting our customers in all 50 states, Canada, and Mexico. With HQs in Somerset, NJ and Mclean, VA, 22nd Century has 14 offices throughout the United States. As part of our unrelenting focus on quality and compliance, 22nd Century Technologies’ delivery is based on Certified Matured Processes including CMMI L3 Dev & SVC, ISO 20000, ISO 27001, and ISO 9001 quality processes. With a strong focus on the public sector, 22nd Century currently holds government contracts with 14 out of 15 Federal Executive agencies including DoD, 37 other Federal agencies, 50 States, 115+ Local agencies, and 37 School Districts. In the last three years, we have expanded our services to Fortune 500 and other commercial clients and currently support 80+ commercial clients.

Recognized among “Best Company to Work For” by Forbes, 22nd Century Technologies, Inc., consistently exceeds our clients’ expectations by focusing on their absolute satisfaction with jobs while keeping our employees motivated.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Skills

  • (XSS) Cross Site Scriptingunmatched
  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Bash Scriptingunmatched
  • Best Practicesunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Computingunmatched
  • Code Reviewsunmatched
  • Communication Skillsunmatched
  • Communications Protocolsunmatched
  • Computer Hackingunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Cryptographyunmatched
  • GPEN - GIAC Penetration Testerunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Incident Responseunmatched
  • Information/Data Security (InfoSec)unmatched
  • Injectionsunmatched
  • Internet Applicationunmatched
  • Internet Securityunmatched
  • Javaunmatched
  • Metasploitunmatched
  • Penetration Testingunmatched
  • People Managementunmatched
  • Policy Developmentunmatched
  • Problem Solving Skillsunmatched
  • Process Improvementunmatched
  • Python Programming/Scripting Languageunmatched
  • Regulationsunmatched
  • Risk Analysisunmatched
  • SQL (Structured Query Language)unmatched
  • SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
  • Scripting (Scripting Languages)unmatched
  • Secure Codingunmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Protocolsunmatched
  • Software Developmentunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • Telecommunicationsunmatched
  • Test Automationunmatched
  • Testingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Web Browsersunmatched
  • Willing to Travelunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder