Talent.com
Web Application Security Tester

Web Application Security Tester

Foxhole TechnologySmyrna, GA, United States
23 hours ago
Job type
  • Full-time
Job description

Web Application Security Tester

Job Locations

US-GA-Smryna

Job ID

2025-2014

Category

CyberSecurity

Type

Regular Full-Time

Clearance Required

Secret

Overview

Title : Web Application Security Tester

Location : Herndon, VA- Remote in States Foxhole is registered to do business

Clearance : Active DoD Secret

Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs. Our talented employee-owners provide agile, scalable services and solutions that solve operational gaps, operate critical systems, and protect and secure the enterprise - across the organization and around the world.

Support the Web Application Security Program (WASP) mission to ensure that security is integrated systematically and comprehensively throughout the Software Development Life Cycle (SDLC).

Job Description

Perform security reviews of web application architectures, APIs, and supporting infrastructure.

  • Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using industry-standard tools.
  • Conduct application spidering, fuzzing, and business logic abuse testing to identify vulnerabilities.
  • Execute Web Application Penetration Testing against modern frameworks (e.g., React, Angular, Node.js, Django, Flask, .NET Core).
  • Test APIs using REST and GraphQL fuzzing, schema validation, and security automation.
  • Identify and validate vulnerabilities such as :
  • OWASP Top 10
  • Business Logic flaws
  • API Security vulnerabilities (OWASP API Top 10)
  • Authentication and authorization weaknesses
  • Deserialization and injection flaws
  • Conduct manual exploit validation beyond automated tool output to reduce false positives.
  • Develop and maintain test automation scripts using frameworks like Burp Suite Extender API, ZAP scripting, and custom Python tools.
  • Integrate security testing into CI / CD pipelines using GitLab CI, GitHub Actions, Jenkins, or Azure DevOps.
  • Utilize SCA (Software Composition Analysis) tools to identify vulnerable dependencies (e.g., Snyk, Dependency-Check, Black Duck).
  • Implement the Common Weakness Scoring System (CWSS) and assist in Common Vulnerability Scoring System (CVSS) ratings for prioritization.
  • Generate technical reports and provide remediation guidance to developers, system owners, and ISSOs.
  • Provide monthly and annual program metrics including trends in vulnerability classes, remediation timelines, and residual risk.

Minimum Requirements

  • Active DoD Secret security clearance
  • 5 + years of progressive incident response experience
  • DoD IAT II required certification / s ( one of the following ) : CCNA-Security, CySA+ (CSA+), GICSP, GSEC, Security+ CE, CND, SSCP, GWAPT, OSWE, eWPT
  • CSSP-AUrequired certification / s ( one of the following ) : GSNA, CISA
  • Required Tools & Hands-On Skills

    Web Security Testing & Automation : Burp Suite Pro, OWASP ZAP, Postman, Fiddler, mitmproxy.

  • SAST / DAST : Checkmarx, Fortify, Veracode, SonarQube, Acunetix, AppScan.
  • SCA (Software Composition Analysis) : Snyk, OWASP Dependency-Check, Black Duck, Mend.
  • Fuzzing & Exploit Development : AFL, Peach Fuzzer, boofuzz.
  • API Security Testing : Postman, Insomnia, ReadyAPI, Burp Suite extensions for GraphQL / REST.
  • CI / CD Security Integration : GitLab CI, Jenkins, GitHub Actions, Azure DevOps with security plugins.
  • Containers & Cloud Security (preferred) : Docker, Kubernetes, AWS Inspector, Prisma Cloud.
  • Desired Experience / Certifications

  • Strong knowledge of the OWASP Top 10 and OWASP ASVS.
  • Familiarity with CWE, NIST 800-53 / 171, and DISA STIGs.
  • Hands-on experience with scripting languages (Python, Bash, PowerShell, JavaScript).
  • Familiarity with DevSecOps practices and secure coding guidelines.
  • Ability to communicate complex findings clearly to both technical and non-technical stakeholders.
  • More Information

    Requirements of position : Think analytically, effective verbal and written communication skills, make decisions, observe / remember details, interpret data, concentrate on tasks, adjust to change, handle stress / emotions. Regular attendance, maintain work schedule, attend meetings, meet deadlines, keyboard / type, handle confidential information, use math / calculations, stay organized, operate office equipment, may direct others. May be exposed to dust / dirt, humidity, and noise.

    Foxhole Technology is an Equal Opportunity Employer and makes hiring decisions without regard to race, color, religion, sex (including pregnancy, childbirth and sexual orientation), national origin, age, disability, genetic information, military / veteran status, or any other protected class.

    Need help finding the right job?

    We can recommend jobs specifically for you!

    Click here to get started.

    Create a job alert for this search

    Application Security • Smyrna, GA, United States

    Related jobs
    • Promoted
    Technology & Privacy Associate

    Technology & Privacy Associate

    5 LegalAtlanta, GA, US
    Full-time
    A leading national and international and top 100 Am Law top firm is looking for highly qualified associates to join their Privacy and Technology Practice. The candidate needs to have 3-6 years of ex...Show moreLast updated: 30+ days ago
    • Promoted
    M516- (764117)Cybersecurity Engineer

    M516- (764117)Cybersecurity Engineer

    FHRAtlanta, GA, US
    Full-time
    Our client has an opening for a Cybersecurity Engineer 3 (764117).This position is up to 5 months with the option of extension. The client is located in Richmond, VA.IT security or cloud security ro...Show moreLast updated: 30+ days ago
    • Promoted
    CS Software Quality Assurance Engineer

    CS Software Quality Assurance Engineer

    KNAPPKennesaw, GA, US
    Full-time
    At KNAPP (pronounced K-NAP, not Nap!), we “Make Complexity Simple” by offering intelligent solutions for digitizing and automating everything from production and distribution to the las...Show moreLast updated: 30+ days ago
    • Promoted
    FSQA Technician

    FSQA Technician

    Home ChefLithia Springs, GA, US
    Full-time
    Founded in 2013, Home Chef is the leading meal solutions company with both a retail and online presence.Kroger grocery stores, Home Chef is committed to inspiring and enabling more people to cook s...Show moreLast updated: 30+ days ago
    • Promoted
    Cybersecurity Analyst

    Cybersecurity Analyst

    Apex InformaticsAtlanta, GA, US
    Full-time
    The Georgia Department of Human Services, Office of Information Technology, is seeking a qualified candidate for the temporary contractor staffing position of Cybersecurity Analyst as part of the I...Show moreLast updated: 30+ days ago
    • Promoted
    !TSTestQv1!

    !TSTestQv1!

    PruittHealthNorcross, GA, US
    Full-time
    The Account Care Leader must possess strong leadership skills and maintain a high level of professionalism.The Account Care Leader is responsible for leading in a proactive, mature, consistent and ...Show moreLast updated: 30+ days ago
    • Promoted
    KSU Asset Support

    KSU Asset Support

    Abacus Service CorporationKennesaw, GA, US
    Full-time
    Short Description : Place RFID tags on assets, attach barcodes to doors, and update the RFID information in our tracking system. Complete Description : On-Site Work Possibility of extensions.Qualifica...Show moreLast updated: 30+ days ago
    • Promoted
    Principal, Cyber Engineering Tech Ops

    Principal, Cyber Engineering Tech Ops

    Cargill RussiaAtlanta, GA, United States
    Full-time
    Cargill’s size and scale allows us to make a positive impact in the world.Our purpose is to nourish the world in a safe, responsible and sustainable way. We are a family company providing food, ingr...Show moreLast updated: 9 days ago
    UX / UI Analyst

    UX / UI Analyst

    DRT Strategies, Inc.Atlanta, GA, US
    Full-time
    Quick Apply
    Overview DRT Strategies delivers expert management consulting and information technology (IT) solutions to large federal agencies, the U. Navy, state and local government and commercial clients in h...Show moreLast updated: 30+ days ago
    • Promoted
    Principal, Cyber Engineering & Tech Ops

    Principal, Cyber Engineering & Tech Ops

    Cargill, IncorporatedAtlanta, GA, United States
    Full-time
    The Principal, Cyber Engineering & Technology Operations leads the strategic design, implementation and improvement of cybersecurity protective technologies within the organization.As a recognized ...Show moreLast updated: 30+ days ago
    • Promoted
    Cyber Security Specialist

    Cyber Security Specialist

    sugar foods corporationVilla Rica, GA, US
    Full-time
    Atlanta, GA (Preferred Home Base).CISO (Virtual Chief Information Security Officer).Sugar Foods LLC is a privately owned company with production facilities in Georgia, Massachusetts, California, an...Show moreLast updated: 30+ days ago
    Senior Application Security Engineer

    Senior Application Security Engineer

    ImagineX ConsultingAtlanta, GA, US
    Full-time
    Quick Apply
    ImagineX is a Software Company whose goal is to help our clients transform their businesses by embracing emerging technologies such as Cloud, Cybersecurity, and Mobile. Through the use of our experi...Show moreLast updated: 30+ days ago
    • Promoted
    Principal, Cyber Engineering & Tech Ops (Data Security)

    Principal, Cyber Engineering & Tech Ops (Data Security)

    Cargill, IncorporatedAtlanta, GA, United States
    Full-time
    The Principal, Cyber Engineering & Technology Operations leads the strategic design, implementation and improvement of cybersecurity protective technologies within the organization.As a recognized ...Show moreLast updated: 2 days ago
    Enterprise Vulnerability Analyst

    Enterprise Vulnerability Analyst

    Tier4 GroupAtlanta, Georgia, United States
    Full-time +1
    Quick Apply
    Are you a Vulnerability Management Operations professional that excels in problem-solving, can serve as a Qualys SME, and drive the operations of a global enterprise company's vulnerability managem...Show moreLast updated: 6 days ago
    • Promoted
    Cybersecurity Administrator

    Cybersecurity Administrator

    TireHub, LLCAtlanta, GA, US
    Full-time
    At TireHub we move more than tires – we move businesses forward, support communities, and help keep America rolling.We call them Hubbers – because they’re at the center of everyth...Show moreLast updated: 4 days ago
    • Promoted
    Data Center Security Officer

    Data Center Security Officer

    SecuritasLithia Springs, GA, US
    Full-time
    We help make your world a safer place.Securitas is a global company that offers the most advanced and sustainable security solutions in the industry. We are located in 47 countries and have 355,000 ...Show moreLast updated: 3 days ago
    • Promoted
    Cybersecurity Analyst

    Cybersecurity Analyst

    Apidel TechnologiesAtlanta, GA, US
    Full-time
    The Department of Human Services, Office of Information Technology, is seeking a qualified candidate for the temporary contractor staffing position of Cybersecurity Analyst as part of the Informati...Show moreLast updated: 30+ days ago
    • Promoted
    Cyber Security

    Cyber Security

    TradeJobsWorkForce30157 Dallas, GA, US
    Full-time
    Cyber Security Job Duties : Safeguards information system assets by identifying and solvin...Show moreLast updated: 30+ days ago
    The Home Depot is hiring : Senior User Experience Designer- Identity and Security

    The Home Depot is hiring : Senior User Experience Designer- Identity and Security

    MediabistroAtlanta, GA, United States
    Full-time
    Senior User Experience Designer- Identity and Security.Senior User Experience Designer- Identity and Security.This Senior UXD role is highly technical and focused on building our identity and secur...Show moreLast updated: 30+ days ago
    • Promoted
    Senior DevSecOps Engineer

    Senior DevSecOps Engineer

    Together For TalentAtlanta, GA, US
    Full-time
    Headquartered in Atlanta GA with remote teams nationwide, we are a booming software company focusing on 3D imaging and AI-driven analytics for intelligent asset management and predictive maintenanc...Show moreLast updated: 30+ days ago