Talent.com
Cybersecurity Penetration Testing Engineer
Cybersecurity Penetration Testing EngineerTalencia • Charlotte, NC, United States
Cybersecurity Penetration Testing Engineer

Cybersecurity Penetration Testing Engineer

Talencia • Charlotte, NC, United States
7 days ago
Job type
  • Full-time
  • Quick Apply
Job description

Title : Cybersecurity Penetration Testing Engineer Application & API Security

Location : Charlotte, NC

Job Summary

We are seeking a Cybersecurity Penetration Testing Engineer specializing in Application and API Security to perform advanced offensive security testing across business-critical systems.

The ideal candidate will have hands-on expertise with Burp Suite Professional , deep knowledge of offensive security methodologies, and the ability to identify, exploit, and communicate vulnerabilities effectively.

You will collaborate closely with development, DevSecOps, and risk teams to embed secure coding practices and support remediation efforts within the Secure SDLC .

Experience Required

5 8 years of total experience in web, mobile, or API penetration testing

Minimum 3+ years of hands-on experience in offensive security testing

Key Responsibilities

1. Penetration Testing & Vulnerability Assessment

Conduct manual and automated penetration tests on web, mobile, and API applications.

Leverage Burp Suite Professional for intercepting, modifying, and exploiting traffic.

Perform source code assisted testing to uncover deep logic flaws.

Simulate real-world attack scenarios aligned with OWASP Top 10, SANS 25, and API Security Top 10 frameworks.

Identify vulnerabilities in authentication, authorization, input validation, and session management.

2. API Security Testing

Perform penetration testing of REST and GraphQL APIs, including JWT / OAuth / token testing.

Validate logic flaws, parameter tampering, and insecure microservice communication.

Utilize tools such as Postman, Burp Suite, and OWASP ZAP for fuzzing and payload injection.

Assess API schema issues, rate limiting, and sensitive data exposure.

3. Offensive Security & Exploitation

Develop and execute proof-of-concept (PoC) exploits to demonstrate impact.

Simulate attacker TTPs following the MITRE ATT&CK and CWE frameworks.

Perform targeted testing for authentication bypass, privilege escalation, and deserialization flaws.

Demonstrate advanced exploitation techniques to enhance vulnerability validation.

4. Reporting & Remediation Support

Produce detailed technical reports with clear risk ratings, reproduction steps, and mitigations.

Collaborate with engineering and DevSecOps teams to support patching and secure code remediation.

Participate in vulnerability triage, retesting, and remediation validation cycles.

Present results to both technical teams and executive stakeholders in clear, actionable terms.

5. Security Process & Continuous Improvement

Integrate testing results into CI / CD pipelines to enable DevSecOps automation .

Contribute to secure coding guidelines and developer training initiatives.

Stay up to date with emerging attack trends, new CVEs, and offensive tools.

Develop internal scripts, extensions, or automation workflows to improve testing efficiency.

Technical Skills

Core Tools & Techniques

Expert-level proficiency in Burp Suite Professional (Intruder, Repeater, Decoder, Extender).

Familiarity with OWASP ZAP, Nmap, Metasploit, SQLmap, DirBuster, Hydra, Ffuf .

Deep understanding of OWASP Top 10 (Web & API) and CWE Top 25 vulnerabilities.

Strong analytical skills to identify logic-based and authentication-related flaws.

Programming & Scripting

Proficient in at least one scripting language : Python, JavaScript, or Bash .

Ability to write custom scripts or Burp extensions for advanced payloads.

Strong understanding of HTTP / HTTPS, REST, GraphQL, JSON, and XML protocols.

Offensive Security

Hands-on experience in vulnerability exploitation, reverse engineering, or red team engagements .

Familiarity with exploit frameworks and C2 tools (e.g., Cobalt Strike, Empire) is a plus.

Ability to emulate APT-style threat actor behavior .

API / Cloud Security (Preferred)

Knowledge of API gateways (Kong, Apigee) and microservices architectures .

Exposure to cloud-native security testing (AWS, Azure, GCP) and container security (Docker / Kubernetes).

Qualifications

Bachelor s or Master s degree in Computer Science, Cybersecurity, or related field

5 8 years of experience in application or API penetration testing

Strong technical writing and presentation skills for diverse audiences

Preferred Certifications

OSCP / OSWE / OSEP (Offensive Security)

Burp Suite Certified Practitioner (BSCP)

eWPTX / eCPPT / CEH (Practical)

GWAPT / GPEN / GCPN

Create a job alert for this search

Cybersecurity Engineer • Charlotte, NC, United States

Related jobs
Cyber Security Analyst

Cyber Security Analyst

Zone IT Solutions • Charlotte, NC, US
Full-time
Quick Apply
We is seeking a talented Cyber Security Analyst.As a Cyber Security Analyst, you will play a key role in ensuring the security and integrity of our organization's data and systems.Monitor, detect, ...Show more
Last updated: 2 days ago
Cyber Security Engineer

Cyber Security Engineer

Southern Talent Specialists • Charlotte, NC, US
Full-time
Job Description : The Cyber Security Engineer is responsible for second level security event / incident response along with the collection, analysis, and dissemination of cyber threa...Show more
Last updated: 30+ days ago • Promoted
Cyber Defense Architect

Cyber Defense Architect

VirtualVocations • Charlotte, North Carolina, United States
Full-time
A company is looking for a Principal Architect - Cyber Defense.Key Responsibilities Analyze trends in the threat and compliance environment, advising management on risk mitigation and compliance ...Show more
Last updated: 6 days ago
Junior Cybersecurity Engineer

Junior Cybersecurity Engineer

VirtualVocations • Charlotte, North Carolina, United States
Full-time
A company is looking for a Junior Cybersecurity Engineer (Top Secret).Key Responsibilities Deploy and integrate cybersecurity tools and technologies for mission-critical systems Troubleshoot and...Show more
Last updated: 4 days ago
Incident Response Engineer

Incident Response Engineer

VirtualVocations • Charlotte, North Carolina, United States
Full-time
A company is looking for an Incident Response Engineer.Key Responsibilities Resolve customer issues through troubleshooting, collaboration, and research, ensuring customers are informed of their ...Show more
Last updated: 20 days ago
IE Specialist II

IE Specialist II

Pilgrim's • Matthews, NC, US
Full-time
ESSENTIAL DUTIES & RESPONSIBILITIES : .Troubleshoot electrical systems throughout the plant.Help maintain electrical equipment through PM procedures. Assist in instituting new control systems.Rese...Show more
Last updated: 30+ days ago • Promoted
Cyber Security Consultant

Cyber Security Consultant

VirtualVocations • Charlotte, North Carolina, United States
Full-time
A company is looking for a Senior Cyber Security Consultant.Key Responsibilities Lead the design and implementation of advanced PAM workflows Assist in integrating privileged accounts into the B...Show more
Last updated: 19 days ago
State Licensed Senior Security Architect

State Licensed Senior Security Architect

VirtualVocations • Charlotte, North Carolina, United States
Permanent
Security Architect to lead the design and implementation of secure enterprise and AI-driven architectures.Key Responsibilities Architect and design secure solutions for AI, data analytics, and cl...Show more
Last updated: 1 day ago
Cyber Operations Specialist

Cyber Operations Specialist

United States Army • Charlotte, NC, US
Full-time
As a Cyber Operations Specialist, you’ll use your cyber security skills to defend the Army’s crucial and complex weapons systems, which include satellites, navigation, and aviation systems against ...Show more
Last updated: 5 days ago • Promoted
IAM / Security Infrastucture Architect

IAM / Security Infrastucture Architect

Sumitomo Mitsui Financial Group, Inc. • Charlotte, NC, United States
Full-time
SMBC Group is a top-tier global financial group.Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, ...Show more
Last updated: 1 day ago • Promoted
Cyber Security Engineer

Cyber Security Engineer

VirtualVocations • Charlotte, North Carolina, United States
Full-time
A company is looking for a Cyber Security Engineer.Key Responsibilities : Support the implementation and integration of the new ADR solution to meet security requirements Collaborate with teams t...Show more
Last updated: 30+ days ago
Senior Application Security Engineer

Senior Application Security Engineer

Canary Technologies Corp • Concord, NC, US
Full-time
Canary Technologies is changing the game for hotels with modern software powered by Canary's hospitality-specific AI platform. Canary is utilized by 20,000+ hoteliers in 100+ countries to equip ...Show more
Last updated: 3 days ago • Promoted
Cyber Warfare Technician

Cyber Warfare Technician

U.S. Navy • Newell, NC, US
Full-time +1
To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.As a Cryptologic Technician, you are one of the worlds greatest problem-solvers. Were looking for people with sha...Show more
Last updated: 1 day ago • Promoted
IAM / Security Infrastucture Architect

IAM / Security Infrastucture Architect

SMBC • Charlotte, NC, United States
Full-time
SMBC Group is a top-tier global financial group.Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, ...Show more
Last updated: 1 day ago • Promoted
Architect, Information Security, IAM

Architect, Information Security, IAM

Edwards Lifesciences • Charlotte, NC, United States
Full-time
Innovation starts from the heart.At Edwards Lifesciences, we're dedicated to developing ground-breaking technologies with a genuine impact on patients' lives. At the core of this commitment is our i...Show more
Last updated: 1 day ago • Promoted
Senior Security Architect

Senior Security Architect

TradeJobsWorkForce • 28034 Dallas, NC, US
Full-time
Senior Security Architect Job Duties : Enhances security team accomplishments and competence by planning deliver...Show more
Last updated: 30+ days ago • Promoted
DevSecOps Security Architect

DevSecOps Security Architect

VirtualVocations • Charlotte, North Carolina, United States
Full-time
A company is looking for a DevSecOps Senior Lead Security Architect.Key Responsibilities Lead security risk assessments and provide recommendations for risk mitigation across enterprise and produ...Show more
Last updated: 4 days ago
Senior Threat Hunter

Senior Threat Hunter

VirtualVocations • Charlotte, North Carolina, United States
Full-time
A company is looking for a Senior Threat Hunter to perform intelligence-driven network defense and support incident response capabilities. Key Responsibilities Design and run custom analysis model...Show more
Last updated: 30+ days ago