Analyze security findings, including risk analysis and root cause analysis. Must be US citizen (must be willing to submit to federal, state, and local……
*Technical Setup:* Reliable, high-speed internet access and your own laptop or desktop computer. This is a flexible, remote position perfect for someone who……
Familiarity with console certification guidelines and platform-specific testing practices. Experience with bug tracking and test management tools such as Jira,……
Bachelor’s degree from an accredited college or university with a major in computer science, information systems, engineering, business, or a related scientific……
Skills and knowledge required for success in this position attained through experience and education (Bachelor’s Degree in computer science, mathematics,……
IAAP, DHS Trusted Tester, Deque University, or Section 508 certification. Axe, WAVE, Deque or similar accessibility tools. 3+ years of Accessibility Testing.…
Create and Implement test scripts wherever possible utilizing automated test tools including Selenium or Open Source tools. Record and document testing results.…
Document and demonstrate knowledge of solutions by developing documentation, reviewing test plans, developing test cases, and entering test findings when……
Prepare detailed reports and communicate findings to technical and non-technical stakeholders. HHS, OMB, GAO, OIG, congressional data calls, federal stakeholder……
Desarrollar y ejecutar planes de prueba, casos de prueba y scripts de prueba para garantizar la funcionalidad y calidad de los productos de software.…
Design, develop, and execute performance test plans on multiple projects, through analysis of requirements, documenting results and working with teammates to……
You will work across Epic's web app, iOS and Android apps, and the services behind them, partnering closely with product and engineering throughout the……
Degree in computer/engineering related field. Code and assist in the design of software components, units and modules for clients. MS (3YRS) or BS (5YRS) of.…
Significant experience at designing positive and negative unit tests, functional tests, integration tests, and end-to-end tests for multi-tiered, highly complex……
A. Using tool to see what happened to tracking. A. Using tool to see what happened to tracking. Good understanding of markup languages (HTML, XML, etc.).…
Must be US citizen (must be willing to submit to federal, state, and local background checks and other requirements). The development of novel attack methods.…
Utilize open source tools or develop custom scripts for automating tests to validate software products involving both back-end processing systems and Web-based……
Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on……
Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on……
O Game systems (UI/Combat/Questing/Store/tools etc.). Communicating status to PD/Dev teams as well as Management and working with a cross functional team that……
Use social engineering to identify improvement for security awareness and education. Proficient in using packet analyzer tools like Wireshark and tcpdump.…
Explaining the accessibility requirements associated with the WCAG 2.1 level A/AA principles and guidelines to technical and non-technical audiences.…
Work closely with development team to develop and execute test strategies, plans, and test cases based on requirements. Execute backend testing in SQL Server.…
Experience: Have one year of related specialty IT experience (for example, but not limited to: system engineering, network engineering, information security,……
High school diploma with a minimum of two (2) years of professional experience in software quality assurance, software development, or a related technical field……
Use AI to find out how well the skills on your resume fit this job description.
Black Lantern Security is a Services Oriented Company
Black Lantern Security is built around the ingenuity, passion, and determination of our Operators and Analysts
No one "mastermind"
No "cult of personality"
Competitive compensation and benefits
Healthy work-life balance
Project-based engagements that play to the team's strengths
Web Application Penetration Tester
Location: Remote
Required:
Must be US citizen (must be willing to submit to federal, state, and local background checks and other requirements).
Experience in performing penetration testing on enterprise networks, web applications, and mobile applications.
Familiarity with common web vulnerabilities including: XSS, XXE, SQL Injection, Deserialization Attacks, File Inclusion/Path Traversal Attacks, Server-side Request Forgery, Remote Execution Flaws, Server Configuration Flaws and Authentication Flaws.
Experience in testing web-based APIs (i.e. REST, SOAP, XML, JSON).
Experience in designing and documenting pragmatic remediation guidance for discovered vulnerabilities.
Experience developing actionable intelligence based on open source intelligence (OSINT) gathering.
Experience with 1 or more scripting languages such as Bash, Python, Perl, PowerShell, etc.
Solid understanding of OWASP testing methodology.
Familiarity with front-end web application frameworks (i.e. AngularJS, Bootstrap, etc).
Capable of working effectively and efficiently with minimal supervision.
Strong written and verbal English language skills.
Demonstrated ability to:
Adhere to the highest standards of honesty and scientific and business integrity.
Think critically about complex problems and situations.
Consider emerging vulnerabilities and threats from within the context of organizational risk and business impact(s).
Develop novel attack vectors based on newly discovered vulnerabilities.
Possess a basic understanding of regulatory standards and requirements including the Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI-DSS), and the Gramm-Leach-Bliley Act (GLBA).
Preferences:
Web application development or source code review experience.
Strong knowledge of Windows and Linux operating systems.
Working knowledge of containerized applications and container-based security controls and configurations.
Possess current professional certification (i.e. GWAPT, OSCP, OSCE, GPEN)
Responsibilities:
Conduct assessments of web applications, mobile applications, databases, client-side applications and tools, and APIs.
Execute manual and automated code analysis to assess the quality and security of source code.
Perform pre-assessment research and preparation including reconnaissance, documentation and configuration review, and customer interviews.
Develop custom tools and exploits.
Analyze security findings, including risk analysis and root cause analysis.
Generate comprehensive reports, including detailed findings, exploitation procedures, and mitigations.
Develop and deliver walkthrough(s), proof(s) of concept (PoCs), articles, and formal presentations.
Execute verification and validation testing for customer mitigations and fixes.