Penetration Tester (Java) - Contract Job at Experienced Recruiting Partners, Albany, NY

L05hU3FYVFBxNnRjeXc3ZEd3ZFMxQklqWUE9PQ==
  • Experienced Recruiting Partners
  • Albany, NY

Job Description

Job Category listing: Technical Subject Matter Specialist (Senior)

Contract Role
Location: Hybrid Capital Region NY (4 days/month)

A Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats.

Requirements:

  • Bachelor’s degree in a related software field with 6+ years in a Dev Sec role.
  • Core Java coding experience.
  • Previous job background as an engineer and Dev Sec position on a large scale public enterprise scale application.

Key Responsibilities:

  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Collaborate with Development teams to understand application architecture and find security weaknesses early.
  • Collaborate with Testing teams to integrate with manual and automation testing.
  • Provide guidance on secure coding and how to fix vulnerabilities.
  • Stay updated on Java security threats and best practices.
  • Help improve secure development processes (SDLC).
  • Assist in responding to security incidents related to Java vulnerabilities, current published NIST CVE.
  • Clearly document and report findings, including technical details, risk assessment, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Contribute to security policies for Java development and deployment.
  • Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses’ browser tokens and cache manipulation and Production vs. none prod architecture.
  • Familiar with MITRE ATT&CK Framework.

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Minimum of 6 years of Development/Security experience
  • Experience in Penetration Testing/Ethical Hacking with a focus on Java application security.
  • Strong knowledge of Java programming and its security practices as well as scripting experience.
  • Proficiency in web application security principles (e.g., OWASP).
  • Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques.
  • Experience with penetration testing tools like Burp Suite, Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
  • Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.

Preferred Qualifications:

  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.
  • Experience with scripting languages (e.g., Python, Bash).
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations like HIPAA.
  • Experience with API testing

Job Tags

Contract work,

Similar Jobs

Steris Corporation

Operating Room Equipment Service Technician Job at Steris Corporation

 ...At STERIS, we help our Customers create a healthier and safer world by providing innovative healthcare and life science product and service solutions around the globe. Position Summary The Surgical Service Representative acts as Trusted Advisor to STERIS Customers... 

Amazing Care Pediatric Outpatient Therapy

Pediatric Licensed Professional Counselor Job at Amazing Care Pediatric Outpatient Therapy

Join Our Team at Amazing Care Pediatric Outpatient Therapy Where Passion Meets Purpose! About Us: Amazing Care Pediatric Outpatient Therapy formerly known as Straka Pediatric Therapies is a leading provider of pediatric therapy services in Colorado Springs,...

Envisions

Life Skills Instructor Job at Envisions

 ...college students or those seeking additional income. Community Engagement: Participate in various community activities and volunteering opportunities with the individuals we serve. Therapeutic Activities: Experience unique settings through our horse therapy programs... 

Sycurio.

Customer Success Manager (USA) Job at Sycurio.

 ...The Customer Success Manager facilitates a superlative customerexperience for Sycurio customers...  ...value of their investment in Sycurioservices. They are the customers trusted...  ...management or managing delivery through virtual cross functional teams ~ Effective cross... 

RAM Partners, LLC

Assistant Property Manager Job at RAM Partners, LLC

 ...About Us RAM Partners, LLC, is a full-service real estate management company that manages more than 80,000 apartments throughout the...  ...Overview Icon Ferguson Farm is looking for an Assistant Property Manager with financial experience. Making a career change...