Jobs and Careers
TR

Cybersecurity Engineer- Web Application Pen Tester

Truist
United Statesfull_timeVerifiedPosted 21 Feb 2025

About the role

The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.

Need Help?

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:

Regular

Language Fluency:  English (Required)

Work Shift:

1st shift (United States of America)

Please review the following job description:

Are you a skilled and motivated Web Application Penetration tester and want to join our pentest team? The ideal candidate will be responsible for conducting thorough security assessments of our web applications, identifying vulnerabilities, and working closely with development teams to enhance our overall security posture.

Essential Duties and Responsibilities

Following is a summary of the essential functions for this job.  Other duties may be performed, both major and minor, which are not mentioned below.  Specific activities may change from time to time. 

1. Schedule and conduct demo sessions with application teams to understand the functionality and architecture of target applications

2. Perform comprehensive penetration tests on a set list of web applications, adhering to industry-standard best practices for each test

3. Utilize a variety of tools including Burp Suite, Metasploit, Kali Linux, Nessus, and other relevant hacking tools

4. Conduct testing across diverse environments, including on-premises, APIs, AWS, Azure infrastructures

5. Document and report vulnerabilities, including detailed explanations, reproduction steps, and potential impacts

6. Provide clear and actionable recommendations for remediation to development teams

7. Conduct retests to verify the successful resolution of identified vulnerabilities Stay updated with the latest web application security threats and testing methodologies

Qualifications

Required Qualifications:

The requirements listed below are representative of the knowledge, skill and/or ability required.  Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

1. Bachelor’s degree and five years of experience in systems engineering or administration or an equivalent combination of education and work experience

2. In-depth knowledge in applied enterprise information security technologies including but not limited to firewalls, intrusion detection/prevention systems, network operating systems, identity management, database activity monitoring, encryption, content filtering, and Mainframe security

3. Previous experience in planning and managing IT projects

Preferred Qualifications:

1. 1-3 years of experience in web application penetration testing or equivalent experience with platforms such as HackTheBox, TryHackMe, Proving Grounds, VulnHub or GitHub

2. Demonstrated ability to discover and exploit web application vulnerabilities

3. Experienced in using penetration testing tools such as Burp Suite, Metaspoit, and Nessus

4. Familiarity with cloud environments

5. Strong understanding of web technologies, protocols, and common security vulnerabilities

6. Excellent written and verbal communication skills for reporting and presenting vulnerabilities

7. Understanding of networking fundamentals such as TCP/IP, subnetting, and the OSI model

8. Working knowledge of common network protocols such as HTTPS, SMB, SNMP, and LLMNR

9. Familiarity with the concept of the Software Development Life Cycle (SDLC) and how security practices are integrated within software development

10. Understanding of industry-standard security frameworks such as MITRE ATT&CK.

11. Knowledge of the OWASP framework and the OWASP Top 10

12. Self-Starter with a strong drive for continuous learning and improvement

13.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Truist

View company profile →