Logo for ITR Group

Cybersecurity Penetration Tester

Role overview

Qualifications

  • 7+ years of cybersecurity experience with increasing responsibility in penetration testing
  • 5+ years of hands-on penetration testing experience focused on web applications and APIs within enterprise environments
  • Strong knowledge of web application security vulnerabilities, including OWASP Top 10
  • Advanced proficiency with Burp Suite, Nmap, and common exploitation frameworks

Responsibilities

  • Conduct end-to-end penetration testing engagements, including scoping, exploitation, validation, and reporting
  • Perform security assessments of web applications and APIs, identifying vulnerabilities and recommending effective remediation strategies
  • Utilize industry-standard security testing tools such as Burp Suite, Nmap, and exploitation frameworks to identify security risks
  • Document vulnerabilities clearly and provide actionable remediation guidance for engineering teams

About the company

ITR Group logo

ITR Group

Staffing & Recruiting

At ITR Group, we match ideal IT consultants with unique clients and projects—fast and effectively—time and time again. In short, right fit is where we earn our keep. We excel in this critical space because we place the emphasis where it matters: on knowing. Knowing our consultants and contractors and what makes them tick. Knowing our clients and their particular needs. This knowledge helps us make the smart connections between the two sides of our business—and allows everyone to succeed. This is also why connecting with you is important us, whether you are a consultant with IT skills looking for your next placement, or a client looking for the right experience for your next project. Email, or, better yet, call us and see where ITR Group can help you connect smarter. Specialties: • Enterprise Project Management • Business Intelligence • Mobile Development, Mobile UI/UX • App Development including .NET and Java development • Systems and Application Architecture • Business Analysis • Data Analysis, Data Warehousing, Database Development and DBA including SQL Server/Oracle • QA Testing and analysis

Company details

IndustryStaffing & Recruiting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Long term contract consulting opportunity for an experience Penetration Test. 
Client Requirements: 
  • Must be W2 hourly (no C2C)
  • Work authorization requirements: US Citizen or GC holder

Seeking an experienced Penetration Tester to identify, assess, and validate security vulnerabilities across web applications, APIs, and enterprise systems. This role will lead end-to-end penetration testing engagements, partner closely with engineering teams to remediate findings, and help strengthen the organization's overall security posture through proactive testing and risk assessments.

Key Responsibilities

  • Conduct end-to-end penetration testing engagements, including scoping, exploitation, validation, and reporting.
  • Perform security assessments of web applications and APIs, identifying vulnerabilities and recommending effective remediation strategies.
  • Utilize industry-standard security testing tools such as Burp Suite, Nmap, and exploitation frameworks to identify security risks.
  • Develop Python or Go scripts to automate testing activities and improve penetration testing workflows.
  • Document vulnerabilities clearly and provide actionable remediation guidance for engineering teams.
  • Collaborate with development and engineering teams to validate fixes and verify vulnerability remediation.
  • Support secure development initiatives by identifying risks early and contributing to threat modeling activities.
  • Assist with PCI-related penetration testing and compliance efforts as needed.
  • Contribute to bug bounty programs by validating, triaging, and escalating reported vulnerabilities.
  • Continuously evaluate and improve penetration testing methodologies, tools, and processes.
  • Mentor junior team members and provide technical guidance on penetration testing best practices.

Required Qualifications

  • 7+ years of cybersecurity experience with increasing responsibility in penetration testing.
  • 5+ years of hands-on penetration testing experience focused on web applications and APIs within enterprise environments.
  • Strong knowledge of web application security vulnerabilities, including OWASP Top 10, authentication and authorization flaws, and injection attacks.
  • Advanced proficiency with Burp Suite, Nmap, and common exploitation frameworks.
  • Experience developing automation or testing scripts using Python or Go.
  • Strong analytical, communication, and documentation skills with the ability to deliver clear, actionable security findings.
  • Proven experience collaborating with engineering teams to validate and remediate vulnerabilities.

Preferred Qualifications

  • Experience testing mobile applications, embedded systems, hardware, or third-party/vendor platforms.
  • Familiarity with PCI penetration testing requirements and regulatory compliance.
  • Experience supporting or managing bug bounty programs.
  • Knowledge of threat modeling and identifying security risks during application design and development.
ITR Group offers a competitive compensation and benefits package, including medical, dental, and 401(k) for eligible employees. The W2 pay range for this type of role is approximately $74.00 - $97.00 per billable hour. This range is an estimate and not a guarantee of compensation. The final rate will be determined by factors such as experience, market trends, and specific job assignments. Discover more about how ITR Group connects top talent with leading client opportunities.
 
ITR Group is an Equal Opportunity Employer. We do not discriminate against applicants on the basis of their race, color, national origin, religion, creed, disability, age, sex, sexual orientation, gender identity, marital status, familial status, or status with regard to public assistance, or membership or activity in a local human rights commission.
 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Penetration Tester Related jobs

Other jobs at ITR Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.