FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in application security testing, including penetration testing and vulnerability assessments across various platforms, with a strong focus on cloud security and compliance standards. Proficient in scripting for automation and effective communication of technical findings to diverse audiences.
Highest-signal resume keywords
Penetration TestingCloud Security TestingApplication Security (OWASP Top 10)Offensive Security Tools (Burp Suite, Metasploit)Scripting (Python, Bash, PowerShell)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Penetration TestingVulnerability AssessmentApplication SecurityCloud Security TestingScripting (Python, Bash, PowerShell)NetworkingOperating Systems (Linux/Windows)Containerization (Docker/Kubernetes)Vulnerability ManagementCompliance Standards (PCI-DSS, SOC 2, ISO 27001)
Soft Skills
Strong Written CommunicationStrong Verbal CommunicationCollaboration
Tools & Technologies
Burp SuiteMetasploitNmapNessusCobalt Strike
Industry Keywords
Threat ModellingSCASASTDASTRed Team ExercisesAdversary EmulationAutomated Scanning ToolsTechnical ReportingSecure Coding PracticesEmerging Threats
Tech Stack
Tools & technologiesAWSAzureCloudDockerGoogle Cloud PlatformKubernetesLinuxPython
About the role
Key responsibilities & impact- Conduct application security testing (Threat modelling, SCA, SAST, DAST) across web, mobile, and API platforms to identify vulnerabilities such as those in the OWASP Top 10
- Perform vulnerability assessments across internal and external networks, systems, and cloud infrastructure
- Execute penetration tests (black-box, gray-box, and white-box) against cloud environments (AWS, Azure, GCP), including IAM misconfigurations, storage exposure, container security, and serverless architectures
- Simulate real-world attack scenarios, including red team exercises, social engineering, and adversary emulation
- Analyze and validate findings from automated scanning tools to eliminate false positives
- Develop custom scripts, tools, or exploits to test specific attack vectors as needed
- Document findings in detailed technical reports with clear risk ratings, business impact, and remediation recommendations
- Present findings to technical teams and leadership in a clear, actionable manner
- Collaborate with engineering and DevOps teams to support secure coding practices and remediation efforts
- Stay current with emerging threats, attack techniques, CVEs, and cloud security research
- Contribute to the development of internal security testing methodologies, playbooks, and tooling
- Support compliance efforts (e.g., PCI-DSS, SOC 2, ISO 27001) through testing evidence and reporting
Requirements
What you’ll need- 4+ years of experience in penetration testing, red teaming, or offensive security roles
- Strong understanding of web application security (OWASP Top 10, API security, authentication/authorization flaws)
- Hands-on experience with cloud security testing across AWS, Azure, and/or GCP
- Proficiency with common offensive security tools (e.g., Burp Suite, Metasploit, Nmap, Nessus, Cobalt Strike)
- Scripting/programming skills (Python, Bash, PowerShell, or similar) for tool development and automation
- Solid understanding of networking, operating systems (Linux/Windows), and containerization (Docker/Kubernetes)
- Experience with vulnerability management and reporting tools
- Strong written and verbal communication skills, with the ability to translate technical findings for non-technical audiences.
Benefits
Comp & perks- Competitive pay
- Meaningful equity at an early stage
- Real flexibility on hours, location, and how you do your best work
- A technical team that takes security seriously and will actually listen to you
