Location: Albany, NY
Security Clearance: None
Job Type: Full-Time
Target Salary Range*: $90,000 - $105,000
- This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary
A Penetration Tester with a focus on Java application security identifies, exploits, and supports remediation of vulnerabilities in Java applications to help guard against cyber threats.
- Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
- Identify security flaws in Java code using automated and manual methods.
- Create and use custom exploits to test application security, simulating attacker tactics.
- Manipulate URLs, query parameters, and application browser data to identify penetration avenues.
- Validate and assess browser tokens, cache manipulation, and production versus non-production architecture.
- Assist in responding to security incidents related to Java vulnerabilities and current published NIST CVEs.
- Collaborate with development teams to understand application architecture and identify security weaknesses early.
- Collaborate with testing teams to integrate security testing with manual and automated testing.
- Provide guidance on secure coding and vulnerability remediation.
- Help improve secure development lifecycle processes.
- Contribute to security policies for Java development and deployment.
- Clearly document and report findings, including technical details, risk assessments, and recommended solutions.
- Communicate findings and recommendations to both technical and non-technical staff.
- Stay updated on Java security threats and best practices.
- Apply familiarity with the MITRE ATT&CK Framework.
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- Minimum of 6 years of development or security experience. [Required]
- Experience in penetration testing or ethical hacking with a focus on Java application security.
- Experience with penetration testing tools such as Burp Suite and Metasploit.
- Familiarity with Fortify on Demand SAST and DAST tools.
- Strong knowledge of Java programming and Java security practices.
- Scripting experience.
- Proficiency in web application security principles, including OWASP.
- Knowledge of common web vulnerabilities, including SQL injection and cross-site scripting, and exploit techniques.
- Strong understanding of cryptography and secure communication protocols, including SSL/TLS.
- Excellent problem-solving and analytical skills.
- Strong communication skills.
- High ethical standards and confidentiality.
- Familiarity with the MITRE ATT&CK Framework.
- Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or other industry security certifications.
- Experience with scripting languages, such as Python or Bash.
- Experience with secure code review for Java.
- Familiarity with cloud security testing.
- Experience with mobile application penetration testing.
- Knowledge of regulations such as HIPAA.
- Experience with API testing.
#LI-BM1