Senior Penetration Tester Job at GDR Defense, Vermont

Wlp2RWd1TU94akhOZHFaRkorWlg1RmVMa1E9PQ==
  • GDR Defense
  • Vermont

Job Description

"Join GD Resources for dynamic opportunities in business management and IT, where innovation meets excellence."




About the Company:

GD Resources is a Veteran Women-Owned Business Management and Information Technology company committed to excellence. GD Resources provides dynamic opportunities for veterans and professionals alike to contribute to innovative projects and drive success in a collaborative and supportive environment. Join us to make a difference, advance your career, and grow with a company that values integrity, diversity, and continuous improvement.

Senior Penetration Tester / Application Security Engineer

Location: Remote (U.S.-based preferred)
Duration: 1.5 Months

Clearance: Preferred (Public Trust / Secret / Top Secret varies by project)

About the Role

We are seeking a highly skilled Senior Penetration Tester / Application Security Engineer to join our cybersecurity team. This role focuses on identifying, exploiting, and validating vulnerabilities across web applications, APIs, mobile platforms, and enterprise infrastructure.

You will perform real-world attack simulations, partner with engineering teams, and provide actionable remediation guidance to strengthen the organization's security posture.

Key Responsibilities

  • Conduct web application, API, mobile, and network penetration testing
  • Perform manual and automated vulnerability assessments
  • Identify and exploit vulnerabilities aligned with OWASP Top 10
  • Execute end-to-end penetration testing lifecycle :
    • Reconnaissance
    • Scanning & enumeration
    • Exploitation
    • Post-exploitation
    • Reporting
  • Perform threat modeling and risk assessments
  • Test authentication, authorization, and session management controls
  • Conduct API security testing (REST, SOAP, GraphQL)
  • Simulate real-world attack scenarios (red team-style engagements)
  • Validate vulnerabilities and develop proof-of-concepts (PoCs)
  • Collaborate with DevOps and engineering teams to drive remediation
  • Produce detailed technical reports and executive summaries
  • Support secure SDLC and DevSecOps initiatives
  • Stay current with emerging threats, tools, and techniques

Required Qualifications

  • 5+ years of experience in penetration testing or application security
  • Strong expertise in:
    • Web application security vulnerabilities (OWASP Top 10)
    • API security testing
    • Network and infrastructure security
  • Hands-on experience with tools such as:
    • Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, SQLMap
  • Experience with manual testing techniques (not just automated scans)
  • Knowledge of:
    • Authentication & access control flaws (IDOR, OAuth, JWT, etc.)
    • Common exploits (SQLi, XSS, CSRF, SSRF, RCE)
  • Familiarity with scripting (Python, Bash, or similar)
  • Experience with Linux-based testing environments (e.g., Kali Linux)
  • Strong understanding of:
    • TCP/IP, DNS, firewalls, and network protocols
  • Excellent communication and reporting skills

Preferred Qualifications

  • Experience with:
    • Cloud security (AWS, Azure, GCP)
    • Containerized environments (Docker, Kubernetes)
    • CI/CD and DevSecOps integration
  • Background in:
    • Red teaming or adversary simulation
    • Threat modeling methodologies (e.g., STRIDE)
  • Certifications such as:
    • OSCP, CEH, Security+, CySA+, GPEN, GWAPT
  • Experience working in federal or regulated environments (NIST, RMF, FedRAMP)

Job Tags

Remote work

Similar Jobs

Shorebreak Security, Inc

Application Penetration Tester (Senior - Principal) Job at Shorebreak Security, Inc

Hiring Web and Mobile Application Penetration TestersJob Title Application Penetration Tester (Senior Principal)Shorebreak Security...  ..., self-disciplined, motivated application penetration test professionals to join our team.Live where you want and work remotely... 

Venture Together

Chief Compliance Officer Job at Venture Together

 ...must embrace the philosophies Venture Together adheres to including Person Centered Planning and the DSP Core Competencies.Chief Compliance OfficerJOB SUMMARYThe Chief Compliance Officer (CCO), as directed by the Agencys Chief Executive Officer, will be responsible... 

-

Retail Merchandiser Job at -

Be a Part Time Retail Merchandiser working for REVLON - a leader in the cosmetic merchandising industry! You've worked with the rest - now work with the BEST! We value our merchandisers as members of our family! A competitive hourly pay rate based on experience Drive-time...

Merck & Co.

Clinical Quality Operations Manager - Remote Job at Merck & Co.

Job DescriptionIn partnership with the Clinical Quality Operations Lead (CQOL and Head of CQO, the CQOM is accountable for the execution of operational quality activities within the assigned therapeutic area.- This includes operational quality management and inspection ...

vial fotheringham

Associate Attorney - Insurance Defense Job at vial fotheringham

VF Law, a leading homeowner association law firm, is seeking an Associate Attorney licensed to practice in Arizona for its Mesa, AZ office. A minimum of 1-3 years of experience in civil litigation, particularly insurance defense is preferred. A portable book of business...