Penetration Tester / Offensive Security Testing - (W2 ONLY) - 100% REMOTE ROLE

Zillion Technologies, Inc. All jobs
1 month(s) ago
Job Overview
Company Zillion Technologies, Inc.
Job Typecontract
CategoryInformation Technology and Engineering
First Seen 1 month(s) ago

Job Description

"""Work sponsorship is not available for this position. Applicants must be a United States citizen Green Card holder or EAD Green Card holder at the direction of our client"". NO THIRD PARTIES PLS THIS IS A DIRECT CLIENT REQUIREMENT ! Those authorized to work without sponsorship are encouraged to apply please. Reach Saakshi Sahni - 703-955-1070 Email saakshi(at)zilliontechnologies(dot)com // 7039551070 Penetration Tester Duration Long Term Ongoing Project Direct Banking Client 100% Remote $80/hr w2 ""Work sponsorship is not available for this position. Applicants must be a United States citizen Green Card holder or EAD Green Card holder at the direction of our client"". This is the targeted compensation range for this role per year. Please note that this range is provided as a guideline and the final offer will be based on several factors including but not limited to skillset and competencies level of experience education certifications and location. Benefits We offer a comprehensive benefits package including medical dental vision and disability insurance 401(k). Compensation $80/hr w2 Description As a member of our Attack & Pentest team you will serve as a frontline analyst responsible for validating prioritizing and driving the closure of security vulnerabilities across the enterprise. You will assess findings for exploitability and business risk retest applications and infrastructure after remediation and work directly with engineering teams to ensure issues are resolved effectively and on schedule. This is a hands-on technical role that requires both offensive security skills and the ability to communicate clearly with developers architects and leadership. Responsibilities Triage – Review and validate incoming vulnerability reports from Mythos assess severity exploitability and business impact de-duplicate and enrich findings with reproduction steps and evidence Retesting – Perform targeted retesting of remediated vulnerabilities to confirm fixes are effective and complete document pass/fail results with technical evidence Tracking & Remediation Support – Monitor remediation timelines against SLAs coordinate with development and infrastructure teams to ensure timely closure escalate aging findings per policy Reporting – Maintain accurate records in the vulnerability management platform produce weekly status reports on open/closed/overdue findings contribute to executive-level metrics Collaboration – Partner with application security DevOps and engineering teams to provide remediation guidance and technical context for findings Process Improvement – Identify patterns in recurring vulnerabilities recommend process or tooling improvements to reduce triage backlog Required Qualifications 3+ years of hands-on penetration testing experience (web applications APIs infrastructure) Demonstrated experience triaging vulnerabilities at scale (CVSS scoring CWE/OWASP classification risk-based prioritization) Strong understanding of common vulnerability classes (OWASP Top 10 SANS Top 25) and remediation strategies Experience with vulnerability management platforms (e.g. Jira ServiceNow DefectDojo or similar) Ability to write clear reproducible proof-of-concept exploits and remediation validation reports Familiarity with SDLC integration and working directly with development teams on fix guidance Strong written and verbal communication skills able to translate technical findings for varied audiences Preferred Qualifications Relevant certifications OSCP GPEN GWAPT CEH or equivalent Experience with bug bounty or crowdsourced vulnerability programs Familiarity with financial services regulatory requirements (PCI-DSS FFIEC SOX) Scripting/automation skills (Python Bash Burp extensions) for retesting workflows Experience with CI/CD pipeline security tooling (SAST/DAST integration) Tools & Environment (Preferred Familiarity) Burp Suite Professional Nuclei Caido Git-based workflows and code review Cloud platforms (AWS Azure GCP) security configurations Container/Kubernetes security fundamentals Please send qualified resumes directly to saakshi(at)zilliontechnologies(dot)com // 7039551070 Thanks Saakshi Sahni Zillion Technologies Inc. Director - Talent Acquisition Email saakshi(at)zilliontechnologies(dot)com // 703-955-1070 ""Zillion Technologies is an equal opportunity employer. We do not discriminate on the basis of race color religion sex national origin age disability genetic information veteran status sexual orientation gender identity or any other characteristic protected by applicable federal state or local law."""

Unlock: Sign Up for free / Sign In and use the searches from your home page or the links in the footer.