Penetration Tester

Amatriot Group, LLC
  • Rensselaer, NY
  • $90,000–$105,000 Per Year
  • Instant Apply
30+ days ago

Job Description

Location: Albany, NY
Security Clearance: None
Job Type: Full-Time

Target Salary Range*:$90,000 - $105,000

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary


Position Overview

A Penetration Tester with a focus on Java application security identifies, exploits, and supports remediation of vulnerabilities in Java applications to help guard against cyber threats.


Key Responsibilities

Penetration Testing and Vulnerability Assessment

  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Manipulate URLs, query parameters, and application browser data to identify penetration avenues.
  • Validate and assess browser tokens, cache manipulation, and production versus non-production architecture.
  • Assist in responding to security incidents related to Java vulnerabilities and current published NIST CVEs.

Secure Development and Remediation Support

  • Collaborate with development teams to understand application architecture and identify security weaknesses early.
  • Collaborate with testing teams to integrate security testing with manual and automated testing.
  • Provide guidance on secure coding and vulnerability remediation.
  • Help improve secure development lifecycle processes.
  • Contribute to security policies for Java development and deployment.

Reporting, Communication, and Threat Awareness

  • Clearly document and report findings, including technical details, risk assessments, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Stay updated on Java security threats and best practices.
  • Apply familiarity with the MITRE ATT&CK Framework.

Qualifications

Education

  • Bachelor’s degree in Computer Science, Information Security, or a related field.

Experience

  • Minimum of 6 years of development or security experience. [Required]
  • Experience in penetration testing or ethical hacking with a focus on Java application security.
  • Experience with penetration testing tools such as Burp Suite and Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.

Skills

  • Strong knowledge of Java programming and Java security practices.
  • Scripting experience.
  • Proficiency in web application security principles, including OWASP.
  • Knowledge of common web vulnerabilities, including SQL injection and cross-site scripting, and exploit techniques.
  • Strong understanding of cryptography and secure communication protocols, including SSL/TLS.
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.
  • Familiarity with the MITRE ATT&CK Framework.

Preferred Qualifications

  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or other industry security certifications.
  • Experience with scripting languages, such as Python or Bash.
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations such as HIPAA.
  • Experience with API testing.

#LI-BM1

Numbers & Facts

LocationRensselaer, NY
Salary$90,000–$105,000 Per Year

Skills

  • (XSS) Cross Site Scriptingunmatched
  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Bash Scriptingunmatched
  • Best Practicesunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Computingunmatched
  • Code Reviewsunmatched
  • Communication Skillsunmatched
  • Communications Protocolsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Cryptographyunmatched
  • GPEN - GIAC Penetration Testerunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Incident Responseunmatched
  • Information/Data Security (InfoSec)unmatched
  • Injectionsunmatched
  • Internet Securityunmatched
  • Javaunmatched
  • Metasploitunmatched
  • Penetration Testingunmatched
  • People Managementunmatched
  • Policy Developmentunmatched
  • Problem Solving Skillsunmatched
  • Product Lifecycleunmatched
  • Python Programming/Scripting Languageunmatched
  • Regulationsunmatched
  • Risk Analysisunmatched
  • SQL (Structured Query Language)unmatched
  • SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
  • Scripting (Scripting Languages)unmatched
  • Secure Codingunmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Clearanceunmatched
  • Security Protocolsunmatched
  • Software Developmentunmatched
  • Test Automationunmatched
  • Testingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Web Browsersunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder