Apply Here

  • Job ID:

    Job-1892
  • Job Title:

    Web Application Penetration Tester
  • Location:

    Bay Area, CA
  • Duration:

    1 year+
  • Job Description:

    Must-have requirements-
    • Advanced knowledge web application penetration testing.
    • Extensive knowledge of and proven experience with penetration testing of web applications, and methods and frameworks for identifying and remediating vulnerabilities.
    • In-depth knowledge of OWASP Top 10 and other frameworks.
    • Proficient knowledge of Java, Spring, and Oracle.
    • Working knowledge of Linux and Windows
    DELIVERABLES OR TASKS:
    Provide primary development support:
    • Conduct details penetration tests using common frameworks such as OWASP to discover vulnerabilities.
    • Work closely with the development team to remediate vulnerabilities.
    • Develop automation scripts to re-run security tests and ensure that new vulnerabilities are caught before they are deployed to higher environments.
    • Assist the development team in ensuring that applications are securely designed and developed.
    • Promote high quality, scalability, and timely completion of projects.
    • Ensure that all project documentation is produced in the standard format, that it follows internal documentation.
    • Serve as subject matter expert for all matters related to web application security.
    • Create, test, and implement code changes and integrate them with existing programs as needed.
    • Coordinate meetings/communications with the Claims User Community, as needed.
    • Ensure that all I.T. requirements (documentation, sign-off, and approvals) are completed as per State Fund’s System Engineering Handbook.
    • Provide timely and effective reporting on status of projects.
    Provide primary support:
    • Perform peer code reviews and provide feedback.
    • Work with cross functional teams, including Business, QA, and Operations.
    • Work closely with Business Users to scope and draft functional requirements.
    • Help Users to create test cases, use cases and help with functional testing.
    • Debug the system for certain behavior of the feature(s) and explain it to the Users.
    TECHNICAL KNOWLEDGE AND SKILLS:
    • Advanced knowledge web application penetration testing.
    • In-depth knowledge of OWASP Top 10 and other frameworks.
    • Experience and willingness to work in a fast-paced environment.
    • Development experience in an enterprise-class system with multi-tier architecture
    • Proficient knowledge of Java, Spring, and Oracle.
    • Working knowledge of Linux and Windows
    • Extensive knowledge of and proven experience with penetration testing of web applications, and methods and frameworks for identifying and remediating vulnerabilities.
    • Strong knowledge in project management practices and ability to document processes and procedures as needed.
  • Job Type:

    Contract

 

Hear what our consultants have to say about us…

Soby Oomen

Sr. Oracle Applications Developer

“I have been working at Buxton Consulting for more than 3 years.
Management is very attentive and responsive. Intelligent managers and executives who know their employees and make an effort to ensure that they have everything they need to succeed. Great People to work with.”

Kavnish Gupta

Business Analyst

“I worked for Buxton Consulting as a full time employee for about 5 years between 2013 and 2018.  I worked on various managed projects, inhouse and at client end.  Buxton was very professional in all their dealings with the employee and clients.  The HR team and my Client Relations Manager, always had regular interactions and feedback sessions with me to discuss the project and personal goals. Buxton also handled my Visa and Immigration related work with thorough professionalism and I never had any issues with that. I would definitely recommend Buxton Consulting as an employer and also for short and long term managed projects.”