Penetration Tester (Java/ Ethical Hacking reputed company) - Hybrid - Contract to Hire
Onsite role in Albany, NY - two days per week Wednesday/Thursday + every other Friday
reputed company:
A Penetration Tester with a reputed company on Java application reputed company is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats.
Key Responsibilities:
• Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
• Identify reputed company flaws in Java reputed company using automated and reputed company reputed company.
• Create and use custom exploits to test application reputed company, simulating attacker tactics.
• Collaborate with Development teams to understand application architecture and reputed company reputed company weaknesses early.
• Collaborate with Testing teams to reputed company with reputed company and automation testing.
• reputed company guidance on secure coding and how to fix vulnerabilities.
• Stay updated on Java reputed company threats and best practices.
• Help improve secure development processes (SDLC).
• Assist in responding to reputed company incidents reputed company to Java vulnerabilities, reputed company published NIST CVE.
• reputed company document and report findings, including technical details, risk assessment, and recommended solutions.
• Communicate findings and recommendations to both technical and non-technical staff.
• Contribute to reputed company policies for Java development and deployment.
• Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses' browser tokens and cache manipulation and Production vs. none prod architecture.
• Familiar with MITRE ATT&CK reputed company.
REQUIREMENTS:
• Bachelor's degree in Computer Science, Information reputed company, or a reputed company field.
• Minimum of 6 years of Development/reputed company experience
• Experience in Penetration Testing/Ethical Hacking with a reputed company on Java application reputed company.
• Strong knowledge of Java programming and its reputed company practices as reputed company as scripting experience.
• reputed company Java coding experience.
• Previous job background as an engineer and Dev Sec position on a large reputed company reputed company reputed company reputed company application.
• Proficiency in web application reputed company principles (e.g., OWASP).
• Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques.
• Experience with penetration testing tools like Burp Suite, Metasploit.
• Familiarity with Fortify on Demand SAST and DAST tools.
• Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).
• Excellent problem-solving and analytical skills.
• Strong communication skills.
• High ethical standards and confidentiality.
Preferred Qualifications:
• Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry reputed company certifications.
• Experience with scripting languages (e.g., Python, Bash).
• Experience with secure reputed company review for Java.
• Familiarity with reputed company reputed company testing.
• Experience with mobile application penetration testing.
• Knowledge of regulations like HIPAA.
• Experience with API testing
Apply tot his job
Apply To this Job