Jobs via Dice ยท 5 days ago
Penetration Tester
Delviom LLC is seeking a Penetration Tester to conduct security assessments and penetration testing. The role involves performing Grey Box testing, assessing security controls, and providing detailed findings reports to ensure the security of applications and systems.
Computer Software
Responsibilities
Perform Grey Box penetration testing in isolated, non-production environments (pre-prod, development, or equivalent) unless explicit authorization is granted for production access
Conduct testing in alignment with the OWASP Application Security Verification Standard (ASVS)
Assess security controls including authentication, access control, session management, input validation, business logic, API security, cryptography, logging, and configuration/file access
Adhere to clearly defined scope boundaries, including approved URLs, APIs, systems, account types, and privilege levels
Follow agreed permitted and prohibited testing techniques, with defined escalation and incident reporting procedures
Provide a detailed findings report with CVSS scoring for all identified vulnerabilities
Include step-by-step proof of concept, supported by screenshots, logs, or payloads as evidence
Deliver root cause analysis, business impact assessment, and remediation guidance aligned with OWASP ASVS and secure coding principles
Demonstrate proficiency with security testing tools such as Burp Suite, Nmap, SQLMap, and similar industry-standard tools
Qualification
Required
NATO Secret Clearance Required
Perform Grey Box penetration testing in isolated, non-production environments (pre-prod, development, or equivalent) unless explicit authorization is granted for production access
Conduct testing in alignment with the OWASP Application Security Verification Standard (ASVS)
Assess security controls including authentication, access control, session management, input validation, business logic, API security, cryptography, logging, and configuration/file access
Adhere to clearly defined scope boundaries, including approved URLs, APIs, systems, account types, and privilege levels
Follow agreed permitted and prohibited testing techniques, with defined escalation and incident reporting procedures
Provide a detailed findings report with CVSS scoring for all identified vulnerabilities
Include step-by-step proof of concept, supported by screenshots, logs, or payloads as evidence
Deliver root cause analysis, business impact assessment, and remediation guidance aligned with OWASP ASVS and secure coding principles
Demonstrate proficiency with security testing tools such as Burp Suite, Nmap, SQLMap, and similar industry-standard tools
Company
Jobs via Dice
Welcome to Jobs via Dice, the go-to destination for discovering the tech jobs you want.
Funding
Current Stage
Early StageCompany data provided by crunchbase