SIXGEN Logo

SIXGEN

Senior Web Application Penetration Tester

Posted Yesterday
Remote
Hiring Remotely in Annapolis, MD
100K-135K
Senior level
Remote
Hiring Remotely in Annapolis, MD
100K-135K
Senior level
Conduct web application penetration tests, analyze security findings, report results, and collaborate with teams and clients to enhance security measures.
The summary above was generated by AI

We are seeking a Senior Web Application Penetration Tester to join our growing team. As a Senior Web Application Penetration Tester, you will be challenged to perform endpoint discovery, open source research, web application enumeration, and novel vulnerability analysis/exploitation. This is much more than Burp scans; operators routinely develop custom tooling (in languages such as PHP, Java, and Python) and achieve a deep understanding of target infrastructure/technology in exploitation paths. The assessments are usually a long haul and great for advanced bug bounty hunters who enjoy getting deep in the weeds. Some cloud/Active Directory experience is a plus for post exploitation activities. 

This role resides in our Delivery Department and reports to our VP of Cyber Operations. This position is remote with a 10% travel requirement.

SIXGEN supports cyber and intelligence missions by serving government and commercial organizations as they overcome global cybersecurity challenges. Our highly skilled operators conduct research and assessments based on real-world threats. We simulate adversaries and malicious actors to report details and actionable findings on critical assets and infrastructures. Our program planners advise mission owners to bring rapid solutions to intelligence mission leaders. Using innovative processes, tools, and techniques, we predict and overcome cybersecurity vulnerabilities. Our successes are supported by our diverse team of experienced, technical talent. SIXGEN is growing our support to mission by adding an ambitious Strategic Management Consultant to our team. SIXGEN, Inc. is an Equal Opportunity/Veterans/Disabled Employer.

Core Responsibilities:

  • Conduct assessments of web applications, mobile applications, databases, client-side applications and tools, and APIs.
  • Collaborate with team members and clients to define project scopes, business cases, review test results, and determine remediation steps.
  • Analyze security findings, including risk analysis and root cause analysis.
  • Draft reports and communicate complex security concepts and test findings to clients and stakeholders.
  • Participate in client meetings, communicate clearly and openly on incremental progress, and inform the team of any help needed on impediments and roadblocks.
  • Generate comprehensive reports, including detailed findings, exploitation procedures, and mitigation.

Required Skills and Experience:

  • Ability to participate in cybersecurity control testing engagements for the customer's network, websites, apps and cloud technologies.
  • 5 years of Web Application Penetration Tester experience. 
  • OSCP, OSWA, OSWE, CRTO, CBBH, GWAPT, or other relevant, hands-on certification. OSCP preferred. 
  • Must have experience in web application penetration testing.
  • Knowledge of FISMA and NIST 800 series standards.
  • Experience in network mapping, vulnerability scanning, and penetration and web application testing.
  • Experience using approved test protocols and procedures to conduct network and application-level penetration tests.
  • Experience attending client meetings, recording internal and technical client interviews and preserving the contents of reports and memoranda.
  • Proficiency in using scanning tools like Nessus and NMap, as well as penetration tools like the Kali Linux suite, Burpsuite and Metasploit.
  • Must be willing to travel as needed.
  • Must be able to obtain Secret Clearance.
  • Experience in script writing and crafting of payloads.

Additional Details:

  • Job Location: Maryland, Northern Virginia, remote 
  • Clearance Requirement: Must be able to obtain Secret Clearance
  • Travel: Up to 10%

Compensation & Benefits

  • Competitive salary
  • Employer-paid health insurance premiums (medical, dental, vision)
  • Employer-paid short/long term disability insurance and basic life/AD&D insurance
  • 401K with a 4% employer contribution
  • Professional development reimbursement options available (training, certification, education, etc)​
  • Flexible and remote work policies for most positions
  • Paid Time Off (PTO) at a rate of three (3) weeks plus one (1) day per year of service up to four (4) weeks annually
  • 11 paid holidays per calendar year​

At SIXGEN, we are committed to fair and equitable compensation practices. The anticipated salary range for this role is $100,000 - $135,000 per year, depending on experience and qualifications. This range reflects our compensation philosophy, which takes into account various factors including the candidate's relevant experience, education, skills, LCATs rates and position level, and market competitiveness. In addition to base salary, employees may be eligible for other forms of compensation to include our growth incentive program, incentives and benefits. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role. Please note that this range is subject to change and should be considered as a guideline rather than a definitive figure.

We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work.

SIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.

Top Skills

Burpsuite
Java
Kali Linux
Metasploit
Nessus
Nmap
PHP
Python

Similar Jobs

2 Hours Ago
Remote
United States
128K-143K Annually
Mid level
128K-143K Annually
Mid level
Artificial Intelligence • Information Technology • Machine Learning • Security • Software • Cybersecurity • Generative AI
As a Professional Services Engineer, you will implement security products, collaborate with customers, and solve complex technical problems while traveling up to 80%.
Top Skills: Linux Command LineLog ManagementProgramming LanguagesScriptingSIEM
4 Hours Ago
Remote
Hybrid
2 Locations
135K-160K Annually
Senior level
135K-160K Annually
Senior level
Fintech • Mobile • Social Impact • Financial Services
As the IT Operations Manager, you will oversee day-to-day IT operations, audit management, security operations, and cross-functional collaboration to enhance the company's IT and security frameworks.
Top Skills: Cloud InfrastructureFirewallsGCPIntrusion Detection SystemsIso 27001NistOktaSecurity FrameworksSIEM
4 Hours Ago
Easy Apply
Remote
Hybrid
United States
Easy Apply
135K-205K Annually
Senior level
135K-205K Annually
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
The Senior Security Operations Engineer will lead incident responses, conduct forensic investigations, monitor security events, and collaborate with teams to implement security solutions.
Top Skills: AWSGCPPythonSiem Tools

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account