Penetration Tester (Java) - Contract Job at Experienced Recruiting Partners, Albany, NY

WDZRUG1QWjh0NkJhNm5qb1FGY1ZsYTZBdWc9PQ==
  • Experienced Recruiting Partners
  • Albany, NY

Job Description

Job Category listing: Technical Subject Matter Specialist (Senior)

Contract Role
Location: Hybrid Capital Region NY (4 days/month)

A Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats.

Requirements:

  • Bachelor’s degree in a related software field with 6+ years in a Dev Sec role.
  • Core Java coding experience.
  • Previous job background as an engineer and Dev Sec position on a large scale public enterprise scale application.

Key Responsibilities:

  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Collaborate with Development teams to understand application architecture and find security weaknesses early.
  • Collaborate with Testing teams to integrate with manual and automation testing.
  • Provide guidance on secure coding and how to fix vulnerabilities.
  • Stay updated on Java security threats and best practices.
  • Help improve secure development processes (SDLC).
  • Assist in responding to security incidents related to Java vulnerabilities, current published NIST CVE.
  • Clearly document and report findings, including technical details, risk assessment, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Contribute to security policies for Java development and deployment.
  • Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses’ browser tokens and cache manipulation and Production vs. none prod architecture.
  • Familiar with MITRE ATT&CK Framework.

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Minimum of 6 years of Development/Security experience
  • Experience in Penetration Testing/Ethical Hacking with a focus on Java application security.
  • Strong knowledge of Java programming and its security practices as well as scripting experience.
  • Proficiency in web application security principles (e.g., OWASP).
  • Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques.
  • Experience with penetration testing tools like Burp Suite, Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
  • Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.

Preferred Qualifications:

  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.
  • Experience with scripting languages (e.g., Python, Bash).
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations like HIPAA.
  • Experience with API testing

Job Tags

Contract work,

Similar Jobs

The Compost Crew

Roll-Off Driver - CDL Job at The Compost Crew

 ...Develop your career as an expert Roll-Off Driver at Compost Crew If youre committed to safety, service and teamwork, talk to us! As a Compost Crew Driver, youll enjoy a great quality of work life and a chance to thrive for the long-term. Join our high-growth organics... 

FLRSH IN Inc.

Charity Fundraising Assistant - Entry Level Job at FLRSH IN Inc.

&##128205; Full-Time | &##128188; Paid Training | &##128176; Weekly Pay | &##128640; Career Growth Opportunities Are you passionate about making a difference and eager to launch a career in nonprofit fundraising? Join us as an Entry-Level Charity Fundraising Assistant...

Robert Half

Investment Analyst at Investment Firm (2+ years) Job at Robert Half

Description Michelle Espejo with Robert Half Finance & Accounting is recruiting for an Investment Analyst at a mission-driven investment firm. This full-time, permanent role is based in San Francisco with a hybrid schedule (3 days in).Join a firm focused on expanding... 

William Vaughan Company

Mason/Bricklayer Job at William Vaughan Company

 ...construction professionals such as carpenters, masons, and laborers to complete projects. Maintain and clean tools and equipment used in masonry work. Follow safety protocols and regulations to ensure a safe working environment. Inspect and assess work sites for quality... 

Coeur d'Alene Resort

Housekeeping Attendant - CdA Resort Job at Coeur d'Alene Resort

 ...Now Hiring: Housekeeping Attendant Help keep our resort sparkling clean and guests feeling at home About Coeur d'Alene Resort: Our upscale resort is dedicated to providing exceptional guest experiences, and our housekeeping team plays a key role in maintaining...