Penetration Tester (Java/ Ethical Hacking focus) - Hybrid - Contract to Hire Job at Experienced Recruiting Partners, Albany, NY

TnpCREg4R2hZdTJHM3cxakFsaUxHSzc2U2c9PQ==
  • Experienced Recruiting Partners
  • Albany, NY

Job Description

Onsite role in Albany, NY – two days per week Wednesday/Thursday + every other Friday

Overview:

A Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats.

Key Responsibilities:

  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Collaborate with Development teams to understand application architecture and find security weaknesses early.
  • Collaborate with Testing teams to integrate with manual and automation testing.
  • Provide guidance on secure coding and how to fix vulnerabilities.
  • Stay updated on Java security threats and best practices.
  • Help improve secure development processes (SDLC).
  • Assist in responding to security incidents related to Java vulnerabilities, current published NIST CVE.
  • Clearly document and report findings, including technical details, risk assessment, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Contribute to security policies for Java development and deployment.
  • Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses’ browser tokens and cache manipulation and Production vs. none prod architecture.
  • Familiar with MITRE ATT&CK Framework.

REQUIREMENTS:

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Minimum of 6 years of Development/Security experience
  • Experience in Penetration Testing/Ethical Hacking with a focus on Java application security.
  • Strong knowledge of Java programming and its security practices as well as scripting experience.
  • Core Java coding experience.
  • Previous job background as an engineer and Dev Sec position on a large scale public enterprise scale application.
  • Proficiency in web application security principles (e.g., OWASP).
  • Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques.
  • Experience with penetration testing tools like Burp Suite, Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
  • Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.

Preferred Qualifications:

  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.
  • Experience with scripting languages (e.g., Python, Bash).
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations like HIPAA.
  • Experience with API testing

Job Tags

Contract work, 2 days per week

Similar Jobs

24-MAG

Remote | Graphic & UX/UI Designer Expert Network — Up to $80/hr Job at 24-MAG

 ...specialised part-time consulting opportunity for experienced Graphic and UX/UI Designers to join an expert network supporting advanced AI...  ...leading AI labs and companies seeking expertise in user experience, interface design, and visual communication. Once approved... 

Toyota of Cool Springs

Service Advisor Job at Toyota of Cool Springs

 ...attitude* High volume mentality* Customer Satisfaction Index focusedWhat We Offer* 401(k) Savings Plan with Employer-Match* Medical Insurance* Dental Plan* Vision Plan* Basic Life Insurance* Accident & Critical Illness Insurance* Paid Vacation* 5-Day Work Week*... 

Royal Oak Nursing and Rehabilitation

Dietary Aide Job at Royal Oak Nursing and Rehabilitation

 ...primary purpose of your job position is to provide assistance in all dietary functions as directed/instructed and in accordance with...  ...policies and procedures. DELEGATION OF AUTHORITY As a Dietary Aide, you are delegated the administrative authority, responsibility,... 

Confidential

Locums Dentist in Washington State Job at Confidential

 ...Your Next Locums Opportunity Pediatric Dentist or General Dentist with Pediatrics experience Setting: Outpatient Schedule: 3 days per week; 8am-5pm Volume: 20-25 patients per day Start: October 15 Coverage needed through January 2025 Why CI Locums... 

Confidential

ESL Teacher Job at Confidential

ESL Teachers in China, look no further!* APPLY NOW FOR FEBRUARY 2022!Low Working Hours! No weekends or nights! No Training Centers!ONLY WORK 7 TO 15 HOURS PER WEEK!Public, International schools, Kindergartens only. COMPENSATION AND BENEFIT PACKAGE Basic Monthly...