SIXGEN Logo

SIXGEN

Senior Web Application Penetration Tester

Reposted 2 Months Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
100K-135K Annually
Senior level
Remote
Hiring Remotely in USA
100K-135K Annually
Senior level
The Senior Web Application Penetration Tester will conduct assessments, analyze security findings, collaborate with clients, and draft detailed reports on vulnerabilities and remediation steps.
The summary above was generated by AI

SIXGEN’s mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and cutting-edge capabilities to uncover vulnerabilities, protect vital systems, and ensure operational superiority in an ever-evolving digital landscape.

POSITION OVERVIEW

Position: Senior Web Application Penetration Tester
Job Type: Full-time
Location: Remote
Clearance Requirements: Must be able to obtain a Secret Clearance
Travel Requirements: Up to 10%

Experience: 5+ years

Salary:$125-$165K


WHAT YOU'LL DO

We are seeking a skilled and motivated Senior Web Application Penetration Tester to join our growing cyber operations team. The ideal candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques, with the ability to identify complex attack paths and develop creative solutions to challenging security problems.

This role goes far beyond automated scanning. Successful candidates will conduct in-depth assessments of web applications, APIs, mobile applications, and supporting infrastructure while leveraging custom tooling, manual testing techniques, and advanced exploitation methodologies to uncover impactful security findings.

KEY RESPONSIBILITIESWeb Application Security Assessments
  • Conduct penetration testing of web applications, APIs, mobile applications, databases, and client-side technologies.
  • Perform application enumeration, endpoint discovery, vulnerability research, and exploitation activities.
  • Identify, validate, and assess vulnerabilities across complex environments.
  • Analyze attack paths and security weaknesses to determine business and operational impact.
Technical Analysis & Research
  • Develop and utilize custom tools, scripts, and payloads to support testing activities.
  • Perform network mapping, vulnerability analysis, and security assessments across applications and supporting infrastructure.
  • Research emerging vulnerabilities, attack techniques, and exploitation methodologies.
  • Support post-exploitation activities involving cloud and enterprise environments when applicable.
Client Engagement & Reporting
  • Collaborate with clients and internal teams to define scope, review findings, and recommend remediation strategies.
  • Communicate technical concepts and findings to both technical and non-technical stakeholders.
  • Produce comprehensive reports, including detailed findings, exploitation procedures, risk analysis, and mitigation recommendations.
  • Participate in client meetings and provide ongoing updates throughout assessment activities.
QUALIFICATIONS
  • 5+ years of experience in web application penetration testing or offensive cybersecurity.
  • Demonstrated experience conducting manual web application security assessments.
  • Knowledge of modern web application vulnerabilities, attack methodologies, and exploitation techniques.
  • Experience with network mapping, vulnerability scanning, and penetration testing methodologies.
  • Familiarity with NIST 800-series standards and cybersecurity best practices.
  • Experience developing scripts, payloads, or custom testing tools.
  • Strong analytical, problem-solving, and communication skills.
Preferred Certifications

One or more of the following certifications is strongly preferred:

  • CWES (preferred)
  • CWEE (preferred)
  • OSCP
  • OSWA
  • OSWE
  • CRTO
  • GWAPT
  • Other relevant hands-on offensive security certifications
PREFERRED QUALIFICATIONS
  • Experience with cloud environments and post-exploitation activities.
  • Experience with Active Directory security assessments.
  • Familiarity with FISMA compliance requirements.
  • Experience supporting government or regulated industry clients.
  • Proficiency with common offensive security tools and frameworks.
COMPENSATION & BENEFITS

At SIXGEN, we are committed to fair and equitable compensation practices. Compensation for this role will be based on experience, qualifications, technical expertise, and overall alignment with the position.

Additionally, SIXGEN offers top-tier benefits for full-time employees, including:

  • Employer-paid health insurance premiums (medical, dental, vision) for you and your family 
  • Employer-paid short/long term disability insurance and basic life/AD&D insurance
  • 401K with a 4% employer contribution
  • Professional development reimbursement options available (training, certification, education, etc)​
  • Flexible and remote work policies for most positions
  • Flexible PTO and holiday schedule

For more information, please reach out to our Director of Human Resources, Amy Maxwell at [email protected].

OUR COMMITMENT

SIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.

We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work.


Similar Jobs

15 Seconds Ago
Remote
United States
128K-216K Annually
Senior level
128K-216K Annually
Senior level
Aerospace • Artificial Intelligence • Computer Vision • Software • Analytics • Defense • Big Data Analytics
Build scalable systems and machine learning models that transform satellite imagery into labeled geospatial data and production computer vision products. Responsibilities include developing data and annotation pipelines, tracking lineage and versioning, deploying inference services, evaluating models, supporting cloud infrastructure, and improving labeling workflows. The role requires strong Python, cloud, containerization, CI/CD, infrastructure-as-code, production support, and deep learning expertise, with preferred experience in GCP, Vertex AI, spatial databases, and satellite imagery.
Top Skills: Ci/CdCloud RunCloud SqlCloud StorageComputer VisionDeep LearningDockerFionaGdalGeopandasGeotiffGoogle Cloud PlatformIamInfrastructure As CodeKubeflow PipelinesMachine LearningPostgisPostgresPythonRasterioShapelyVertex AiVertex Ai PipelinesWorkflow Orchestration
A Minute Ago
Remote or Hybrid
USA
15-20 Hourly
Entry level
15-20 Hourly
Entry level
eCommerce • Fashion • Retail • Sales • Wearables • Design
Provides personalized styling and product recommendations, builds customer relationships, drives sales, processes POS transactions, and maintains stockroom and sales-floor operations. The role requires strong communication, product knowledge, retail experience, teamwork, flexibility for nights and weekends, and the ability to lift and maneuver merchandise.
Top Skills: Omnichannel/Virtual Selling ToolsPoint-Of-Sale (Pos) SystemsSocial Media
16 Minutes Ago
Remote or Hybrid
OH, USA
Expert/Leader
Expert/Leader
Financial Services
Leads infrastructure engineering initiatives across campus, data center, and WAN networks. Designs and implements modernization efforts, resolves complex technical issues, evaluates system impacts, and guides cross-functional delivery. Applies cloud infrastructure expertise across public and private environments, uses scripting and automation, and validates AI-assisted recommendations against resiliency, security, sensitivity, and auditability requirements.
Top Skills: Cloud InfrastructureDhcpDnsEnterprise AiInfrastructure AutomationIpamNetwork SegmentationNetworkingPrivate CloudPublic CloudQosRoutingScripting LanguagesSwitching

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account