Hybrid

Application Security Tester

Job description

Job Title: Application Security Tester

Location: Jersey City, NJ (Hybrid: 3 days Onsite / 2 days REMOTE)

Duration: 6 Months (CONTRACT TO HIRE)

Skills & Experience Needed:

  • Experience in application security testing
  • Preferred knowledge and/or experience of red teaming
  • Experience in conducting red teaming engagements
  • Experience in manually testing applications (non-automated); Ability to test manually and “live off of the land strategies”
  • Experience in application security testing tools such as Burp Suite Professional & Owasp Zap
  • Ability to explain vulnerabilities and weaknesses in OWASP Top 10 and SANS Top 25 to any audience and discuss effective defensive techniques
  • Understanding of MITRE Framework and adversarial methodologies
  • Ability to bypass controls and/or test countermeasures for misconfigurations
  • Certified in OSCP or GWAPT or related offensive security/red teaming certification
  • This is not a penetration testing role. It goes beyond the scope of a traditional pen test

Summary / Description:

  • Being a member of the Application Security team, you will be part of the Technology Risk initiative to support offensive security assessments on applications and provide SME guidance to key projects.
  • This person is responsible for providing technical direction and performing security assessment on applications.
  • The person in this role should possess good understanding of application security testing, red team / adversarial engagements, and penetration testing and related development expertise to guide project initiatives to ensure security best practices are being used.

Responsibilities:

  • Perform red teaming against applications and APIs. 
  • Perform application threat hunting to evaluate risk to applications.
  • Perform manual (non-automated) security testing of applications.
  • Provide the vulnerability information in the predefined report format after performing the testing using manual methodology and tools
  • Generate reports on assessment findings and summarizes to facilitate remediation, document technical issues identified during security assessments
  • Be a subject matter expert and respond to any security engineering questions/ requests related to Application Defense enhancements
  • Collaborate with Security Architects, Product Manager, Risk Managers, and other teams to deliver high quality product.

Dexian is a leading provider of staffing, IT, and workforce solutions with over 12,000 employees and 70 locations worldwide. As one of the largest IT staffing companies and the 2nd largest minority-owned staffing company in the U.S., Dexian was formed in 2023 through the merger of DISYS and Signature Consultants. Combining the best elements of its core companies, Dexian’s platform connects talent, technology, and organizations to produce game-changing results that help everyone achieve their ambitions and goals.

Dexian’s brands include Dexian DISYS, Dexian Signature Consultants, Dexian Government Solutions, Dexian Talent Development and Dexian IT Solutions. Visit https://dexian.com/ to learn more.

Dexian is an Equal Opportunity Employer that recruits and hires qualified candidates without regard to race, religion, sex, sexual orientation, gender identity, age, national origin, ancestry, citizenship, disability, or veteran status.

Apply Now

"*" indicates required fields

This field is hidden when viewing the form
Name*
Accepted file types: pdf, docx, doc, txt, Max. file size: 50 MB.
We are an equal opportunity employer. We honor diversity and are committed to creating an inclusive environment for everyone. Help us get to know you better by responding to these optional questions.
By registering you agree to our Privacy Policy **