43415 - Pen Testing - 100% Onsite

Posted 2 days ago

samprasoftSpring (TX)

SENIORITY

Mid

Apply

About the role

Application Security Testing Contractor Client is looking to bring on an experienced application security testing contractor in order to supplement internal efforts. Candidate should have all of the following technical and professional characteristics as well: Minimum 2 years' experience penetration/vulnerability testing for web and thick-client applications in an enterprise environment Strong understanding of web technologies, e.g. HTTP, HTML, CSS, Forms, Database Connectivity, etc. Understanding of compliance and regulatory requirements such as PCI DSS, SOX, HIPAA, etc. Full grasp and ability to articulate and/or train others on the OWASP Top 10 and related concepts Minimum 1 years' experience with programming and/or scripting in one or more of the following languages:.NET, Java, PHP, Ruby, Perl, Bash, or similar language Minimum 1 years' experience with SQL, including a strong understanding of SQL syntax and the ability to perform basic management of MS SQL databases Ability to perform manual web application vulnerability assessments without the use of automated tools such as web application scanners Ability to capture and analyze network traffic, including ability to discern whether said network traffic contains vulnerabilities and/or sensitive data Have a solid grasp of core security fundamentals and concepts, including knowing one's system, defense in depth, the principle of least privilege, access control, encryption and cryptography, security architecture and design, business continuity and disaster recovery, etc. Minimum 3 years' experience with enterprise-level security control implementations, including Network Intrusion Detection/Prevention (NIDS/NIPS), Corporate Antivirus, Enterprise Web Filtering, Data Loss Prevention, Insider-threat Mitigation, Botnet Detection, etc., as well as demonstrable knowledge of the principles and techniques used to bypass said controls

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this