Manual Application Penetration Tester (Web & API)

Remote Full-time
Job Title:

Manual Application Penetration Tester (Web & API)
Contract Type:

Contract
Role Overview

We are seeking experienced Manual Application Penetration Testers to perform in-depth security testing of web applications, APIs, and mobile applications. This role requires hands-on, offensive security expertise with a strong focus on manual exploitation, business logic testing, and real-world attack simulation.

The ideal candidate can independently execute penetration testing engagements, clearly articulate findings to both technical and non-technical audiences, and guide remediation efforts.
Key Responsibilities
• Perform manual application penetration testing of:
• Web applications
• REST & SOAP APIs
• Mobile applications (iOS/Android – nice to have)
• Thick client applications (where applicable)
• Conduct business logic testing, threat modeling, and application architecture reviews
• Identify and exploit vulnerabilities including (but not limited to):
• IDOR / BOLA
• Authentication & authorization flaws
• Session management issues
• Injection flaws (SQLi, XSS, XXE, etc.)
• Logic flaws missed by automated scanners
• Perform objective-based and abstract penetration testing engagements
• Develop and demonstrate proof-of-concept (PoC) exploits
• Use Burp Suite Pro extensively for manual testing (Repeater, Intruder, Decoder, etc.)
• Present findings via live demos, written reports, and client readouts
• Clearly communicate risks, impact, and remediation guidance
• Work independently with minimal oversight while meeting delivery timelines

Required Qualifications
• 5+ years of recent experience in manual application penetration testing
• Strong experience testing:
• Web applications
• APIs (REST / SOAP)
• Hands-on expertise with Burp Suite Pro
• Proven ability to perform manual exploitation (not scanner-only testing)
• Experience communicating results to both technical and non-technical stakeholders
• Ability to lead remediation discussions and retesting efforts
• Bachelor’s degree in Computer Science, Engineering, or equivalent industry experience

Preferred Qualifications
• Mobile application penetration testing (iOS / Android)
• Experience with tools such as:
• Netsparker
• OWASP ZAP
• Postman / SoapUI
• Experience with OAuth, JWT, and modern authentication mechanisms
• Ethical hacking certifications (preferred, not required):
• GWAPT
• OSWE
• OSWA
• CREST

Nice-to-Have Experience
• Threat modeling frameworks (STRIDE, PASTA, etc.)
• Secure SDLC / DevSecOps exposure
• Client-facing consulting or enterprise security engagements

Apply tot his job

Apply To this Job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Machine Learning Scientist II - Multimodal AI

Remote Full-time

[PART_TIME Remote] Cloud Solutions Architect-

Remote Full-time

Project Manager-Senior

Remote Full-time

Careercusp Data Entry Walgreens Remote ( Remote ) - We're

Remote Full-time

Data Librarian

Remote Full-time

Career with American Airlines:Flight Attendant | Hiring

Remote Full-time

Experienced Remote Data Entry Specialist – Join arenaflex for a Fulfilling Career in Healthcare from the Comfort of Your Home

Remote Full-time

Experienced Remote Customer Service Representative – United States Work From Home Opportunity with arenaflex

Remote Full-time

Territory Account Executive, SMB - Greater Philadelphia, PA

Remote Full-time

Experienced Dutch Speaking Customer Service Representative for Remote Work Opportunities with blithequark

Remote Full-time
← Back to Home