Senior Web Application Penetration Tester
SIXGEN’s mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and cutting-edge capabilities to uncover vulnerabilities, protect vital systems, and ensure operational superiority in an ever-evolving digital landscape. POSITION OVERVIEW Position: Senior Web Application Penetration TesterJob Type: Full-timeLocation: RemoteClearance Requirements: Must be able to obtain a Secret ClearanceTravel Requirements: Up to 10%Experience: 5+ years WHAT YOU'LL DO We are seeking a skilled and motivated Senior Web Application Penetration Tester to join our growing cyber operations team. The ideal candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques, with the ability to identify complex attack paths and develop creative solutions to challenging security problems. This role goes far beyond automated scanning. Successful candidates will conduct in-depth assessments of web applications, APIs, mobile applications, and supporting infrastructure while leveraging custom tooling, manual testing techniques, and advanced exploitation methodologies to uncover impactful security findings. KEY RESPONSIBILITIES Web Application Security Assessments Conduct penetration testing of web applications, APIs, mobile applications, databases, and client-side technologies. Perform application enumeration, endpoint discovery, vulnerability research, and exploitation activities. Identify, validate, and assess vulnerabilities across complex environments. Analyze attack paths and security weaknesses to determine business and operational impact. Technical Analysis & Research Develop and utilize custom tools, scripts, and payloads to support testing activities. Perform network mapping, vulnerability analysis, and security assessments across applications and supporting infrastructure. Research emerging vulnerabilities, attack techniques, and exploitation methodologies. Support post-exploitation activities involving cloud and enterprise environments when applicable. Client Engagement & Reporting Collaborate with clients and internal teams to define scope, review findings, and recommend remediation strategies. Communicate technical concepts and findings to both technical and non-technical stakeholders. Produce comprehensive reports, including detailed findings, exploitation procedures, risk analysis, and mitigation recommendations. Participate in client meetings and provide ongoing updates throughout assessment activities. QUALIFICATIONS 5+ years of experience in web application penetration testing or offensive cybersecurity. Demonstrated experience conducting manual web application security assessments. Knowledge of modern web application vulnerabilities, attack methodologies, and exploitation techniques. Experience with network mapping, vulnerabilit...