This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
In this contingent resource assignment, you may: Consult on or participate in moderately complex initiatives and deliverables within Cyber Security Research and contribute to large-scale planning related to Cyber Security Research deliverables. Review and analyze moderately complex Cyber Security Research challenges requiring in-depth evaluation of variable factors. Contribute to the resolution of moderately complex issues while leveraging solid understanding of policies, procedures, and compliance requirements. Collaborate with client personnel in Cyber Security Research.
Job Responsibility
Conduct manual penetration testing of web applications, APIs, and mobile platforms
Perform authentication, authorization, and business logic testing
Identify, validate, and exploit vulnerabilities beyond automated scanner results
Configure and tune DAST tools to enhance testing coverage
Use industry tools (Burp Suite, WebInspect, Fiddler, etc.) to support manual testing
Triage false positives and validate scan findings
Reproduce and demonstrate security vulnerabilities with clear impact
Document findings with detailed steps, evidence, and remediation guidance
Deliver high-quality reports for both technical and non-technical audiences
Partner with development and security teams to drive vulnerability remediation
Support discussions, walkthroughs, and follow-ups on identified issues
Provide guidance on secure coding and mitigation strategies
Stay up to date on evolving threats, attack techniques, and testing methodologies
Contribute to improvements in testing frameworks and processes
Share knowledge across team through peer reviews and collaboration
Present findings, risks, and recommendations clearly to stakeholders
Support status updates, reporting, and remediation tracking
Requirements
2+ years of hands-on application penetration testing experience (manual testing required)
Experience with DAST tools and validating/triaging vulnerabilities
Strong knowledge of web application security (OWASP Top 10, APIs, authentication/authorization)