Penetration Tester (Java/ Ethical Hacking focus) - Hybrid - Contract to Hire Job at Experienced Recruiting Partners, Albany, NY

MnhDaUFnRlNZQkFQcjgxVHZvVzhYbnArQVE9PQ==
  • Experienced Recruiting Partners
  • Albany, NY

Job Description

Onsite role in Albany, NY – two days per week Wednesday/Thursday + every other Friday

Overview:

A Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats.

Key Responsibilities:

  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Collaborate with Development teams to understand application architecture and find security weaknesses early.
  • Collaborate with Testing teams to integrate with manual and automation testing.
  • Provide guidance on secure coding and how to fix vulnerabilities.
  • Stay updated on Java security threats and best practices.
  • Help improve secure development processes (SDLC).
  • Assist in responding to security incidents related to Java vulnerabilities, current published NIST CVE.
  • Clearly document and report findings, including technical details, risk assessment, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Contribute to security policies for Java development and deployment.
  • Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses’ browser tokens and cache manipulation and Production vs. none prod architecture.
  • Familiar with MITRE ATT&CK Framework.

REQUIREMENTS:

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Minimum of 6 years of Development/Security experience
  • Experience in Penetration Testing/Ethical Hacking with a focus on Java application security.
  • Strong knowledge of Java programming and its security practices as well as scripting experience.
  • Core Java coding experience.
  • Previous job background as an engineer and Dev Sec position on a large scale public enterprise scale application.
  • Proficiency in web application security principles (e.g., OWASP).
  • Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques.
  • Experience with penetration testing tools like Burp Suite, Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
  • Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.

Preferred Qualifications:

  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.
  • Experience with scripting languages (e.g., Python, Bash).
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations like HIPAA.
  • Experience with API testing

Job Tags

Contract work, 2 days per week

Similar Jobs

PRT

Nursery Supervisor Job at PRT

 ...Who are we: From a humble beginning in 1988 with six nurseries, PRT has grown into North America's largest grower of forest seedlings, having grown over 6 billion trees. With 27 Nurseries & 14 Seed Orchards across the US and Canada, we annually cultivate over 63... 

LMG Technology Services LLC

Business Analyst 2 (529601672) Job at LMG Technology Services LLC

 ...experience in the field or in a related area as a senior Business Analyst (Technical) . Familiar with standard concepts, practices, and...  ...under pressure, negotiate among multiple parties, resolve conflicts, and establish and maintain effective working relationships with... 

TWO95 International, Inc

Front-end Developer Job at TWO95 International, Inc

 ...Job Title: Full-Stack Developer Location: Phoenix, AZ Duration: 6+ months Rate...  ...next generation of responsive e-commerce web applications. Designs and develops...  ...technologies: Native JavaScript Front end web technologies, including Angular2, Node... 

Off Leash K9 Training

Professional Dog Trainer Job at Off Leash K9 Training

-Are you looking for a career, not just a job?-Do you love dogs?-Do you love helping people?-Do you possess great customer service skills? We are the locally owned territory of the fastest growing dog training company in the country- Off Leash K9 Training, LLC.... 

Marco Contractors, Inc.

Traveling Construction Superintendent - Retail Job at Marco Contractors, Inc.

Embark on a Nationwide Adventure as a Traveling Construction Superintendent with Marco Contractors! Are you ready to explore the country while advancing your construction career? Marco Contractors is looking for a skilled Traveling Construction Superintendent to join our...