Senior Penetration Tester / Application Security Engineer
$$$
We are looking for a Senior Penetration Tester / Application Security Engineer to perform a comprehensive security assessment of a web application and its APIs.
Project start: approximately Q4
Engagement: project-based / part-time
Main scope: Web Application & API Penetration Testing
Tech Stack
- Drupal with significant custom development
- Vue.js frontend and admin panel
- Java backend
- MongoDB
- React Native for iOS and Android (mobile pentesting may be added later)
Responsibilities
- Perform manual penetration testing of the web application and admin panel
- Conduct API security testing
- Test authentication, authorization, and role-based access controls
- Identify business logic and security vulnerabilities
- Assess the application against OWASP Top 10 and OWASP API Security risks
Prepare a professional penetration testing report with severity levels, vulnerability descriptions, evidence, and remediation recommendations
Requirements
- Strong hands-on experience in Web Application and API Penetration Testing
- Strong manual pentesting skills, not only automated scanning
- Solid experience with Burp Suite and standard security testing tools
- Experience testing custom-built web applications
- Experience preparing professional pentest reports
- Experience with Java, Drupal, or Vue.js is a plus
- Mobile application pentesting experience is a plus, but not required
Required languages
English
B2 - Upper Intermediate
Ukrainian
B2 - Upper Intermediate
Russian
B2 - Upper Intermediate
Published 18 August
19 views
ยท
3 applications
๐
Average salary range of similar jobs in
analytics โ
Loading...