Jobs Companies MKS2 Technologies Ethical Hacker / Penetration Tester-

Sobre este puesto de Ethical Hacker / Penetration Tester- en MKS2 Technologies

MKS2 Technologies · Híbrido · Albany, NY

MKS2 Technologies, LLC, an award-winning high growth small business, creates innovative and customer-centric technology solutions in the areas of Cyber Security, Instructional Design and Training, Software Engineering and IT Support Services to improve the security and well-being of our clients. Our commitment to excellence and our “Mission First” orientation has resulted in steady growth and an expanding client base across government agencies. We have employees nationwide and for the past three consecutive years were named one of the fastest growing Veteran-owned companies in the nation. Please take a moment to browse through our website and learn more about what it means to serve with MKS2.


 

 

Ethical Hacker / Penetration Tester Principal

Location: Hybrid (Remote with travel to Albany, NY twice per month) 
Job Type: Full-Time
Program: NYSoH
Hours: 40 hours per week
Travel: Two trips per month to Albany, NY
Clearance Required: None
Citizenship Requirement: None
Salary: $120,000

Overview

We are seeking an experienced Ethical Hacker / Penetration Tester Principal to join a high-impact cybersecurity team supporting a large-scale enterprise application environment. This role focuses on identifying, exploiting, assessing, and remediating vulnerabilities within Java-based applications and supporting infrastructure. The ideal candidate possesses deep expertise in application security, penetration testing, secure coding practices, and DevSecOps methodologies.

This position requires collaboration with development, testing, and security teams to proactively identify security weaknesses and strengthen application defenses throughout the Software Development Life Cycle (SDLC).

Key Responsibilities

  • Conduct penetration testing and vulnerability assessments of Java applications, APIs, and supporting infrastructure.
  • Perform manual and automated security testing to identify application vulnerabilities.
  • Develop and execute custom exploits to simulate real-world attacker techniques.
  • Analyze application architecture and code to identify security risks and attack vectors.
  • Collaborate with development teams to integrate security early in the SDLC.
  • Partner with QA and automation teams to incorporate security testing into release processes.
  • Review source code and provide secure coding guidance for remediation efforts.
  • Assess browser tokens, session management, caching, and authentication mechanisms.
  • Manipulate URLs, query parameters, browser data, and application workflows to identify exploitation opportunities.
  • Assist in incident response activities related to security vulnerabilities and published CVEs.
  • Create detailed reports outlining findings, risk levels, business impacts, and remediation recommendations.
  • Present security findings to both technical and non-technical stakeholders.
  • Contribute to security standards, policies, and secure development practices.
  • Stay current on emerging threats, attack techniques, and industry best practices.
  • Apply methodologies aligned with the MITRE ATT&CK Framework and OWASP guidelines.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related technical field.
  • Minimum of 6 years of software development and security experience.
  • Prior experience in a DevSecOps, Application Security, Security Engineering, or Penetration Testing role.
  • Strong hands-on Java development experience.
  • Experience supporting large-scale enterprise applications.
  • Knowledge of secure coding principles and application security best practices.
  • Experience performing penetration testing against web applications and services.
  • Strong understanding of OWASP Top 10 vulnerabilities and mitigation techniques.
  • Experience with security testing tools such as:
    • Burp Suite
    • Metasploit
    • Web Proxy Tools
    • Vulnerability Assessment Platforms
  • Experience using Static and Dynamic Application Security Testing tools, including:
    • Fortify on Demand (SAST)
    • Fortify on Demand (DAST)
  • Knowledge of common web vulnerabilities including:
    • SQL Injection
    • Cross-Site Scripting (XSS)
    • Authentication & Authorization Flaws
    • Session Management Vulnerabilities
    • API Security Risks
  • Strong understanding of cryptography and secure communications protocols (SSL/TLS).
  • Excellent analytical, troubleshooting, and problem-solving skills.
  • Strong written and verbal communication abilities.
  • Demonstrated professionalism, ethics, and confidentiality.

Preferred Qualifications

  • OSCP (Offensive Security Certified Professional)
  • GWAPT (GIAC Web Application Penetration Tester)
  • GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)
  • GPEN (GIAC Penetration Tester)
  • LPT (Licensed Penetration Tester)
  • CEH (Certified Ethical Hacker)
  • CISSP (Certified Information Systems Security Professional)
  • Experience with Python, Bash, or other scripting languages.
  • Experience performing secure code reviews for Java applications.
  • Knowledge of cloud security testing methodologies.
  • Mobile application penetration testing experience.
  • Experience conducting API security assessments.
  • Familiarity with HIPAA and regulated environments.
  • Knowledge of vulnerability management and CVE remediation processes.

Desired Technical Expertise

  • Java Security
  • Secure Coding Practices
  • Application Security
  • Penetration Testing
  • Vulnerability Assessments
  • OWASP
  • MITRE ATT&CK Framework
  • SAST/DAST
  • DevSecOps
  • Web Application Security
  • API Security Testing
  • Threat Modeling
  • Risk Assessment

Why Join Us?

  • Work on mission-critical enterprise applications.
  • Collaborate with a highly skilled cybersecurity team.
  • Influence secure development practices across large-scale environments.
  • Exposure to advanced security testing technologies and methodologies.
  • Opportunity to make a direct impact on application security and cyber resilience.

Apply today if you're passionate about offensive security, ethical hacking, and helping organizations build secure applications from the ground up.


 

Diversity creates a healthier atmosphere: MKS2 Technologies is proud to be an Equal Employment Opportunity / Affirmative Action employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.

¿Listo para postularte en MKS2 Technologies?
Postúlate en MKS2 Technologies

Cómo se compara este salario de Penetration Tester

Este puesto paga $120,000/yrpor debajo de el rango típico para los puestos de Penetration Tester.

$104,020 la mediana de $150,680 $238,500

Rango típico $131,500–$198,442/yr, a partir de 52 ofertas comparables de Penetration Tester en JobsRadar (salario anualizado en USD). Ver datos salariales de Penetration Tester →

Empleos similares

Roblox
Senior Offensive Security Engineer
Roblox
⚡ Postúlate pronto San Mateo, CA, United States Presencial $196,750–$243,290
● Nuevo 👁 Visto ✓ Postulado hace 15h
Coupang
Staff Security Engineer (Penetration Tester)
Coupang
⚡ Postúlate pronto Seoul, South Korea Presencial
● Nuevo 👁 Visto ✓ Postulado hace 16h
Sporty Group
Offensive Security Engineer
Sporty Group
⚡ Postúlate pronto Europe - Remote · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 1d
Rockwell Automation
Ethical Hacker
Rockwell Automation
⚡ Postúlate pronto Katowice, Poland Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 1d
Booz Allen Hamilton
Application Penetration Tester
Booz Allen Hamilton
⚡ Postúlate pronto Chantilly, VA Presencial $62,000–$141,000
● Nuevo 👁 Visto ✓ Postulado hace 1d
Coupang
Staff Security Engineer (Penetration Tester)
Coupang
⚡ Postúlate pronto Seattle, USA Presencial $261,000–$261,000
● Nuevo 👁 Visto ✓ Postulado hace 4d
Airbus
Penetration Tester (All Gender)
Airbus
⚡ Postúlate pronto Madrid Area Presencial
● Nuevo 👁 Visto ✓ Postulado hace 4d
BreachLock
Penetration Tester (AEV)
BreachLock
⚡ Postúlate pronto Pune, Maharashtra, India Presencial
● Nuevo 👁 Visto ✓ Postulado hace 4d
RSM
Penetration Tester
RSM
⚡ Postúlate pronto San Salvador Presencial
● Nuevo 👁 Visto ✓ Postulado hace 4d

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en MKS2 Technologies

Ver todos los empleos en MKS2 Technologies →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis