Application Security Pentester, Specialist

Malvern

Saturday, 09 May 2026

Leads and executes penetration tests across a variety of technologies, including web applications, APIs, and AI-enabled systems. Performs manual and automated testing to identify, exploit, and validate vulnerabilities. Conducts other security assessments as needed, including Secure Code Reviews and/or Dynamic Application Security Testing (DAST). Develops detailed assessment reports and presents findings to technical teams and leadership. Coordinates security risk reporting and collaborates with IT sub-divisions, third-party partners, and business units to identify the impact of technology implementations on IT and business operations. Contributes to the evolution of team processes, testing methodologies, standards, and best practices. Maintains subject-matter expertise in common vulnerability classes and attack techniques (e.g., OWASP Top 10, OWASP Top 10 API, SANS Top 25), and remains familiar with relevant security frameworks (e.g., MITRE ATT&CK). Stays current on emerging threats, tools, and offensive security techniques. Participates in special projects and performs other duties as assigned. Qualifications. Minimum five years related work experience with three years experience in IT security or application development. Undergraduate degree in related field or equivalent combination of training and experience. Hands-on experience performing web application, API, and network penetration testing. Preferred experience with Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tooling. Experience in on or more of the following a plus: cloud penetration testing, mobile penetration testing, AI red teaming. Proficiency in at least one programming or scripting language (e.g., Python, Java). Preferred security certifications such as Off. Sec Certified Professional (OSCP), Off. Sec Web Assessor (OSWA), Off. Sec Web Expert (OSWE), GIAC Penetration Tester (GPEN), or GIAC Web Application Penetration Tester (GWAPT).

apply
 
Loading Similar Jobs...
JOBZ is an independent Job Search Engine. JOBZ is not an agent or representative and is not endorsed, sponsored or affiliated with any employer. JOBZ uses proprietary technology to keep the availability and accuracy of its job listings and their details. All trademarks, service marks, logos, domain names, job descriptions and other company descriptions / details are the property of their respective holder. JOBZ does not have its users apply for a job on the J-O-B-Z.com website. Additionally, JOBZ may provide a list of third-party job listings that may not be affiliated with any employer. Please make sure you understand and agree to the website's Terms & Conditions and Privacy Policies you are applying on as they may differ from ours and are not in our control.