Employment type: Employee, Hourly or Salaried
Expected work hours: As needed, up to 32 hours per week.
Reports to: Gavin Klondike
Ongoing Responsibilities Perform manual web application & API penetration testing on customer applications.
Follow industry standard testing methodologies such as OWASP ASVS.
Actively document findings and vulnerability details throughout the testing process.
Collaborate and communicate with the team and our customers on Slack and through our platform.
Provide ongoing remediation verification testing and advice.
Minimum Qualifications Previous experience performing web & API focused penetration testing.
Experience writing clear, concise vulnerability reports.
Ability to work both independently and with a team.
A proficiency in written English as it is the common language of the team.
Nice-to-have Qualifications Experience engaging directly with developers and technical leadership.
Experience in customer service or technical support roles.
Familiarity with DAST technologies.
Familiarity with the OWASP Risk Rating Methodology, CVSS (Common Vulnerability Scoring System), CWE (Common Weakness Enumeration), and articulating real-world business risk for identified vulnerabilities.
Certifications such as those from OffSec.
Employment type: Employee, Hourly or Salaried
Expected work hours: As needed,
up to 32 hours per week.
Reports to: @Gavin Klondike
Ongoing Responsibilities Perform manual web application & API penetration testing on customer applications.
Follow industry standard testing methodologies such as OWASP ASVS.
Actively document findings and vulnerability details throughout the testing process.
Collaborate and communicate with the team and our customers on Slack and through our platform.
Provide ongoing remediation verification testing and advice.
Minimum Qualifications Previous experience performing web & API focused penetration testing.
Experience writing transparent, concise vulnerability reports.
Ability to work both independently and with a team.
A proficiency in written English as it is the common language of the team.
Nice-to-have Qualifications Experience engaging directly with developers and technical leadership.
Experience in customer service or technical support roles.
Familiarity with DAST technologies.
Familiarity with the OWASP Risk Rating Methodology, CVSS (Common Vulnerability Scoring System), CWE (Common Weakness Enumeration), and articulating real-world business risk for identified vulnerabilities.
Certifications such as those from OffSec.