2

Remote Web App Penetration Testing Jobs in California

Remote - United States Description With 30 years of experience in cyber defense, DeepSeas is ... Perform web application assessments aligned to OWASP Top 10 and API security testing standards.

New

Remote Role Responsibilities * Review and evaluate AI-generated outputs related to threat analysis ... Background in areas such as SOC analysis, incident response (DFIR), penetration testing, threat ...

Engineer, Web Apps

San Francisco, CA · On-site +1

$120K - $175K/yr

Our app brings the natural expressiveness of paper into the digital age, empowering millions of ... Our schedules are flexible, our hybrid policy supports remote work when it makes sense, and we have ...

Remote Role Responsibilities * Review and evaluate AI-generated outputs related to threat analysis ... Background in areas such as SOC analysis, incident response (DFIR), penetration testing, threat ...

Remote Role Responsibilities * Review and evaluate AI-generated outputs related to threat analysis ... Background in areas such as SOC analysis, incident response (DFIR), penetration testing, threat ...

Jump in as a lead developer to extend and maintain our React.js web app * Work with APIs * Work ... Collaborate with our local and remote developer team * Help document our app * Perform routine ...

Remote Role Responsibilities * Red team conversational AI models and agents. Conduct jailbreaks ... Cybersecurity skills: penetration testing, exploit development, reverse engineering. * Socio ...

Contract Compensation: $20-$22/hour Location: Remote Role Responsibilities * Red team ... Background in Cybersecurity : penetration testing, exploit development, reverse engineering.

Strong software engineering background is more important here than classic penetration testing ... Web tech stack proficiency: Strong familiarity with JavaScript/TypeScript and Node.js runtime ...

Contract Compensation: $20-$22/hour Location: Remote Role Responsibilities * Red team ... Background in Cybersecurity : penetration testing, exploit development, reverse engineering.

next page

Showing results 1-20

Remote Web App Penetration Testing information

What is the difference between Remote Web App Penetration Testing vs Remote Network Security Analyst?

AspectRemote Web App Penetration TestingRemote Network Security Analyst
CertificationsOSCP, CEH, GPENCompTIA Security+, CISSP, GIAC
Work EnvironmentSecurity consulting firms, tech companies, freelanceCorporate IT teams, government agencies
Primary FocusIdentifying vulnerabilities in web applicationsMonitoring and securing network infrastructure
Tools & TechniquesBurp Suite, OWASP ZAP, SQLmapSIEM, IDS/IPS, network scanners

Remote Web App Penetration Testing focuses on assessing web application security by identifying vulnerabilities, while Remote Network Security Analysts monitor and protect entire network infrastructures. Both roles require cybersecurity certifications and involve security tools, but they target different aspects of an organization's security landscape.

What are the most commonly searched types of Web App Penetration Testing jobs in California? The most popular types of Web App Penetration Testing jobs in California are:
What are popular job titles related to Remote Web App Penetration Testing jobs in California? For Remote Web App Penetration Testing jobs in California, the most frequently searched job titles are:
What job categories do people searching Remote Web App Penetration Testing jobs in California look for? The top searched job categories for Remote Web App Penetration Testing jobs in California are:
What cities in California are hiring for Remote Web App Penetration Testing jobs? Cities in California with the most Remote Web App Penetration Testing job openings:

Penetration Tester

Deep Seas

San Diego, CA • On-site, Remote

Full-time

Posted 2 days ago

New


Job description

Penetration Tester
Department: Offensive Security
Employment Type: Full Time
Location: Remote - United States
Description
With 30 years of experience in cyber defense, DeepSeas is trusted by nearly 1,000 clients around the world, including Fortune 100 enterprises and mid-market organizations, higher education institutions, municipality and local governments, and federal agencies. Known for its programmatic approach to continuously transforming cyber defense programs, DeepSeas is recognized by Gartner as a top 40 provider of MDR and ranked as a top 5 MDR leader in the 2024 Frost Radar™: Global Managed Detection and Response (MDR) Market. In addition to its industry-leading MDR service, DeepSeas offers a full suite of advisory, compliance, and testing services to support clients on their cybersecurity transformation journeys, with an approach to cyber defense that prioritizes technical expertise, tradecraft, and continuous innovation to deliver unparalleled results.
The Penetration Tester is a practicing offensive security professional who independently executes client engagements across DeepSeas' core service lines. This role represents the transition from emerging practitioner to confident, self-sufficient contributor. Penetration Testers own their engagements end-to-end within defined scope, produce client-ready deliverables without heavy oversight, and are developing the depth and breadth needed to tackle increasingly complex environments. This is the primary delivery role on the team and the foundation of the practice's capacity.
Key Responsibilities
Technical Delivery
  • Conduct internal and external network penetration tests including enumeration, exploitation, lateral movement, and post-exploitation within defined scope.
  • Perform web application assessments aligned to OWASP Top 10 and API security testing standards.
  • Conduct basic cloud security assessments (AWS, Azure, GCP) including misconfiguration identification, IAM review, and exposed services enumeration.
  • Bring experience with adversarial engagements such as red team and purple team exercises.
  • Support AI/LLM security assessments including prompt injection, model abuse scenarios, and OWASP LLM Top 10 coverage under senior guidance.

Reporting & Client Communication
  • Produce complete, client-ready findings reports with clear technical narratives, reproduction steps, risk ratings, and remediation guidance.
  • Participate in client kick-off calls and debrief walkthroughs, communicating findings professionally to technical and non-technical stakeholders.
  • Maintain accurate engagement documentation, time tracking, and artifact organization in project management systems.

Professional Growth & Travel
  • Pursue continuous development through assigned training, lab environments, and certification advancement.
  • May be required to travel up to 25% of the time.
  • Candidates must be U.S. citizens and currently reside within the United States.

Skills Knowledge and Expertise
Minimum Qualifications
  • 2-5 years of professional penetration testing or applied offensive security experience; strong candidates with equivalent demonstrated skills will be considered.
  • Proficiency with standard toolsets: Nmap, Metasploit, Burp Suite, Nessus/OpenVAS, BloodHound, or equivalents.
  • Solid understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, AD, VPNs) and common vulnerability classes.
  • Familiarity with at least one scripting language (Python, Bash, or PowerShell) for basic automation and tooling.
  • Exposure to cloud platforms (AWS, Azure, or GCP) and awareness of common cloud misconfiguration patterns.
  • Solid understanding of AI technology in everyday work activities.
  • Strong written communication with the ability to produce accurate, professional-quality findings documentation.

Preferred Qualifications
  • Hands-on penetration testing certification, such as PNPT (TCM Security), OSCP (Offensive Security), CompTIA PenTest+, or eWPT/eJPT with demonstrated experience.

Why DeepSeas?
At Deep Seas, we like to say that heart rates go down, careers take off, and security programs mature. Our values provide the ultimate guide for our daily behavior and decisions. Without these values, we aren't Deep Seas. They preserve the essence of our organization, reflect the personalities of our Deeps (how we affectionately refer to our teammates), and enable us to exceed expectations. Our values are:
  • We are client obsessed.
  • We stand in solidarity with our teammates.
  • We prioritize personal health and well-being.
  • We believe in the power of diversity.
  • We solve hard problems at the speed of cyber.

This is your chance to join a supportive crew of teammates and an industry-leading organization that values opportunities for growth. If DeepSeas sounds like a good fit for you, send us your resume and let's talk!
Information security is everyone's responsibility:
  • Understanding and following DeepSeas's information security policies and procedures.
  • Remaining vigilant and reporting any suspicious activity or possible weaknesses in DeepSeas's information security.
  • Actively participating in DeepSeas's efforts to maintain and improve information security.
  • DeepSeas considers this position is as Moderate Risk with a potential to view/access/download restricted/private client/internal data.
  • This information must be treated with sensitivity and in the most secure manner.
  • HR reserves the right to perform random background/drug screens to ensure the safety of client/DeepSeas data