Remote Clearance Requirements: Must be able to obtain a Secret Clearance Travel Requirements: Up to 10% Experience: 5+ years WHAT YOU'LL DO We are seeking a skilled and motivated Senior Web ...
Remote Clearance Requirements: Must be able to obtain a Secret Clearance Travel Requirements: Up to 10% Experience: 5+ years WHAT YOU'LL DO We are seeking a skilled and motivated Senior Web ...
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Quick apply
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Penetration Tester (Part Time & Remote)
Sterling, VA · On-site +1
$50 - $85/hr
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Penetration Tester (Part Time & Remote)
Sterling, VA · On-site +1
$50 - $85/hr
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Lead Penetration Tester
Leesburg, VA · On-site +1
Hybrid (Leesburg & Remote) Clearance Requirement: Secret Position Overview The Senior Penetration ... This role is responsible for executing authorized penetration testing activities across FAA/DOT ...
Lead Penetration Tester
Leesburg, VA · On-site +1
Hybrid (Leesburg & Remote) Clearance Requirement: Secret Position Overview The Senior Penetration ... This role is responsible for executing authorized penetration testing activities across FAA/DOT ...
Enterprise Cybersecurity Penetration Tester and Operator, Mid
Mclean, VA · On-site +1
$62K - $141K/yr
... testing, including internet, intranet, wireless, mobile devices and applications, and web ... Remote : If this position is listed as remote, there may still be occasions when you are required ...
Enterprise Cybersecurity Penetration Tester and Operator, Mid
Mclean, VA · On-site +1
$62K - $141K/yr
... testing, including internet, intranet, wireless, mobile devices and applications, and web ... Remote : If this position is listed as remote, there may still be occasions when you are required ...
... Web application Testing (Manual Testing skills / Automated tools such as Webinspect, Appscan ... remote access, single sign on, firewalls, vulnerability assessments, and penetration testing.
... Web application Testing (Manual Testing skills / Automated tools such as Webinspect, Appscan ... remote access, single sign on, firewalls, vulnerability assessments, and penetration testing.
Penetration Tester
Fort George G Meade, MD · On-site +1
$86K - $198K/yr
Remote Work: Hybrid Job Number: R0243365 Location: Fort Meade,MD,US Share job via: Share Penetration Tester The Opportunity: Conduct testing and analysis to identify vulnerabilities and potential ...
Penetration Tester
Fort George G Meade, MD · On-site +1
$86K - $198K/yr
Remote Work: Hybrid Job Number: R0243365 Location: Fort Meade,MD,US Share job via: Share Penetration Tester The Opportunity: Conduct testing and analysis to identify vulnerabilities and potential ...
Penetration Tester
Herndon, VA · On-site +1
$86K - $198K/yr
Remote Work: No Job Number: R0236401 Location: Herndon,VA,US Share job via: Share Penetration Tester The Opportunity: Conduct testing and analysis to identify vulnerabilities and potential threat ...
Penetration Tester
Herndon, VA · On-site +1
$86K - $198K/yr
Remote Work: No Job Number: R0236401 Location: Herndon,VA,US Share job via: Share Penetration Tester The Opportunity: Conduct testing and analysis to identify vulnerabilities and potential threat ...
Jr. Cyber Penetration Tester
Arlington, VA · On-site +1
$66K - $106K/yr
Understand common Web Application vulnerabilities like SQLi, XSS, CSRF, and HTTP Flooding. * Experience with penetration testing tools such as Metasploit, Burp Suite, Nmap, etc. * Fundamentals of ...
Jr. Cyber Penetration Tester
Arlington, VA · On-site +1
$66K - $106K/yr
Understand common Web Application vulnerabilities like SQLi, XSS, CSRF, and HTTP Flooding. * Experience with penetration testing tools such as Metasploit, Burp Suite, Nmap, etc. * Fundamentals of ...
Penetration Testing Team Lead
Washington, DC · On-site +1
$130K - $160K/yr
This is a remote position. Responsibilities: * Plans, coordinates and leads red team and penetration testing engagements across FSA systems. * Oversees test planning, execution, and reporting.
Quick apply
Penetration Testing Team Lead
Washington, DC · On-site +1
$130K - $160K/yr
This is a remote position. Responsibilities: * Plans, coordinates and leads red team and penetration testing engagements across FSA systems. * Oversees test planning, execution, and reporting.
Jr Cyber Penetration Tester
Arlington, VA · On-site +1
$66K - $106K/yr
Understand common Web Application vulnerabilities like SQLi, XSS, CSRF, and HTTP Flooding. * Experience with penetration testing tools such as Metasploit, Burp Suite, Nmap, etc. * Fundamentals of ...
Jr Cyber Penetration Tester
Arlington, VA · On-site +1
$66K - $106K/yr
Understand common Web Application vulnerabilities like SQLi, XSS, CSRF, and HTTP Flooding. * Experience with penetration testing tools such as Metasploit, Burp Suite, Nmap, etc. * Fundamentals of ...
... web, mobile, cloud, embedded and AI systems. * Hands-on penetration testing skills across ... Flexible WFH, both remote and in-office opportunities * Fully stocked kitchen, catered lunches, and ...
Quick apply
... web, mobile, cloud, embedded and AI systems. * Hands-on penetration testing skills across ... Flexible WFH, both remote and in-office opportunities * Fully stocked kitchen, catered lunches, and ...
This is the emerging class of LLM-driven penetration-testing agents, built for production use by a ... Remote/WAH requirements: * WAH requirements: Must have the ability to provide a high speed DSL or ...
This is the emerging class of LLM-driven penetration-testing agents, built for production use by a ... Remote/WAH requirements: * WAH requirements: Must have the ability to provide a high speed DSL or ...
This is the emerging class of LLM-driven penetration-testing agents, built for production use by a ... Remote/WAH requirements: * WAH requirements: Must have the ability to provide a high speed DSL or ...
This is the emerging class of LLM-driven penetration-testing agents, built for production use by a ... Remote/WAH requirements: * WAH requirements: Must have the ability to provide a high speed DSL or ...
This is the emerging class of LLM-driven penetration-testing agents, built for production use by a ... Remote/WAH requirements: * WAH requirements: Must have the ability to provide a high speed DSL or ...
This is the emerging class of LLM-driven penetration-testing agents, built for production use by a ... Remote/WAH requirements: * WAH requirements: Must have the ability to provide a high speed DSL or ...
Senior Red Team Operator
Sterling, VA · On-site +1
Apply penetration testing, network analysis, and adversary emulation techniques to identify ... Flexible and remote work policies for most positions * Flexible PTO and holiday schedule For more ...
Senior Red Team Operator
Sterling, VA · On-site +1
Apply penetration testing, network analysis, and adversary emulation techniques to identify ... Flexible and remote work policies for most positions * Flexible PTO and holiday schedule For more ...
Application Developer
Alexandria, VA · Remote
Application Developer Location: Remote Clearance Type: Public Trust * Minimum of 5 years of ... Develop an ASP.NET Core web app that consumes an API * Microsoft Applied Skills: Develop data ...
Application Developer
Alexandria, VA · Remote
Application Developer Location: Remote Clearance Type: Public Trust * Minimum of 5 years of ... Develop an ASP.NET Core web app that consumes an API * Microsoft Applied Skills: Develop data ...
NLM Cloud Engineer III
Bethesda, MD · Remote
$59.50 - $79.50/hr
Experience with vulnerability scanning and penetration testing tools such as Tenable, Prowler ... Deliver day-to-day cloud operations support, including secure remote access, administration of ...
NLM Cloud Engineer III
Bethesda, MD · Remote
$59.50 - $79.50/hr
Experience with vulnerability scanning and penetration testing tools such as Tenable, Prowler ... Deliver day-to-day cloud operations support, including secure remote access, administration of ...
Vulnerability Researcher
Reston, VA · On-site +1
Approval of remote and hybrid work is not guaranteed regardless of work location.For additional ... Cybersecurity penetration testing / cybersecurity Red Team testing / white hat hacking * Military ...
Vulnerability Researcher
Reston, VA · On-site +1
Approval of remote and hybrid work is not guaranteed regardless of work location.For additional ... Cybersecurity penetration testing / cybersecurity Red Team testing / white hat hacking * Military ...
Senior Lead Developer
Washington, DC · Remote
Remediate security vulnerabilities identified through automated scanning or penetration testing ... Responsive web design Backend Technologies * Python frameworks (FastAPI, Flask, or Django) * ...
Senior Lead Developer
Washington, DC · Remote
Remediate security vulnerabilities identified through automated scanning or penetration testing ... Responsive web design Backend Technologies * Python frameworks (FastAPI, Flask, or Django) * ...
Remote Web App Penetration Testing information
What is the difference between Remote Web App Penetration Testing vs Remote Network Security Analyst?
| Aspect | Remote Web App Penetration Testing | Remote Network Security Analyst |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | CompTIA Security+, CISSP, GIAC |
| Work Environment | Security consulting firms, tech companies, freelance | Corporate IT teams, government agencies |
| Primary Focus | Identifying vulnerabilities in web applications | Monitoring and securing network infrastructure |
| Tools & Techniques | Burp Suite, OWASP ZAP, SQLmap | SIEM, IDS/IPS, network scanners |
Remote Web App Penetration Testing focuses on assessing web application security by identifying vulnerabilities, while Remote Network Security Analysts monitor and protect entire network infrastructures. Both roles require cybersecurity certifications and involve security tools, but they target different aspects of an organization's security landscape.
Other
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 16 days ago
Job description
SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and cutting-edge capabilities to uncover vulnerabilities, protect vital systems, and ensure operational superiority in an ever-evolving digital landscape.
POSITION OVERVIEWPosition: Senior Web Application Penetration Tester
Job Type: Full-time
Location: Remote
Clearance Requirements: Must be able to obtain a Secret Clearance
Travel Requirements: Up to 10%
Experience: 5+ years
We are seeking a skilled and motivated Senior Web Application Penetration Tester to join our growing cyber operations team. The ideal candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques, with the ability to identify complex attack paths and develop creative solutions to challenging security problems.
This role goes far beyond automated scanning. Successful candidates will conduct in-depth assessments of web applications, APIs, mobile applications, and supporting infrastructure while leveraging custom tooling, manual testing techniques, and advanced exploitation methodologies to uncover impactful security findings.
KEY RESPONSIBILITIESWeb Application Security Assessments- Conduct penetration testing of web applications, APIs, mobile applications, databases, and client-side technologies.
- Perform application enumeration, endpoint discovery, vulnerability research, and exploitation activities.
- Identify, validate, and assess vulnerabilities across complex environments.
- Analyze attack paths and security weaknesses to determine business and operational impact.
- Develop and utilize custom tools, scripts, and payloads to support testing activities.
- Perform network mapping, vulnerability analysis, and security assessments across applications and supporting infrastructure.
- Research emerging vulnerabilities, attack techniques, and exploitation methodologies.
- Support post-exploitation activities involving cloud and enterprise environments when applicable.
- Collaborate with clients and internal teams to define scope, review findings, and recommend remediation strategies.
- Communicate technical concepts and findings to both technical and non-technical stakeholders.
- Produce comprehensive reports, including detailed findings, exploitation procedures, risk analysis, and mitigation recommendations.
- Participate in client meetings and provide ongoing updates throughout assessment activities.
- 5+ years of experience in web application penetration testing or offensive cybersecurity.
- Demonstrated experience conducting manual web application security assessments.
- Knowledge of modern web application vulnerabilities, attack methodologies, and exploitation techniques.
- Experience with network mapping, vulnerability scanning, and penetration testing methodologies.
- Familiarity with NIST 800-series standards and cybersecurity best practices.
- Experience developing scripts, payloads, or custom testing tools.
- Strong analytical, problem-solving, and communication skills.
One or more of the following certifications is strongly preferred:
- CWES (preferred)
- CWEE (preferred)
- OSCP
- OSWA
- OSWE
- CRTO
- GWAPT
- Other relevant hands-on offensive security certifications
- Experience with cloud environments and post-exploitation activities.
- Experience with Active Directory security assessments.
- Familiarity with FISMA compliance requirements.
- Experience supporting government or regulated industry clients.
- Proficiency with common offensive security tools and frameworks.
At SIXGEN, we are committed to fair and equitable compensation practices. Compensation for this role will be based on experience, qualifications, technical expertise, and overall alignment with the position.
Additionally, SIXGEN offers top-tier benefits for full-time employees, including:
- Employer-paid health insurance premiums (medical, dental, vision) for you and your family
- Employer-paid short/long term disability insurance and basic life/AD&D insurance
- 401K with a 4% employer contribution
- Professional development reimbursement options available (training, certification, education, etc)
- Flexible and remote work policies for most positions
- Flexible PTO and holiday schedule
For more information, please reach out to our Director of Human Resources, Amy Maxwell at amy.maxwell@sixgen.io.
OUR COMMITMENTSIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.
We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work.
About SixGen
Sourced by ZipRecruiter
Industry
Software development
Company size
51 - 200 Employees
Headquarters location
Annapolis, MD, US
Year founded
2014