Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Ethical Hacker / Penetration Tester

$120k

MKS2 Technologies

Job Description

Job Description

MKS2 Technologies, LLC, an award-winning high growth small business, creates innovative and customer-centric technology solutions in the areas of Cyber Security, Instructional Design and Training, Software Engineering and IT Support Services to improve the security and well-being of our clients. Our commitment to excellence and our "Mission First" orientation has resulted in steady growth and an expanding client base across government agencies. We have employees nationwide and for the past three consecutive years were named one of the fastest growing Veteran-owned companies in the nation. Please take a moment to browse through our website and learn more about what it means to serve with MKS2.

 

 

Ethical Hacker / Penetration Tester Principal

Location: Hybrid (Remote with travel to Albany, NY twice per month) 
Job Type: Full-Time
Program: NYSoH
Hours: 40 hours per week
Travel: Two trips per month to Albany, NY
Clearance Required: None
Citizenship Requirement: None
Salary: $120,000

Overview

We are seeking an experienced Ethical Hacker / Penetration Tester Principal to join a high-impact cybersecurity team supporting a large-scale enterprise application environment. This role focuses on identifying, exploiting, assessing, and remediating vulnerabilities within Java-based applications and supporting infrastructure. The ideal candidate possesses deep expertise in application security, penetration testing, secure coding practices, and DevSecOps methodologies.

This position requires collaboration with development, testing, and security teams to proactively identify security weaknesses and strengthen application defenses throughout the Software Development Life Cycle (SDLC).

Key Responsibilities
  • Conduct penetration testing and vulnerability assessments of Java applications, APIs, and supporting infrastructure.
  • Perform manual and automated security testing to identify application vulnerabilities.
  • Develop and execute custom exploits to simulate real-world attacker techniques.
  • Analyze application architecture and code to identify security risks and attack vectors.
  • Collaborate with development teams to integrate security early in the SDLC.
  • Partner with QA and automation teams to incorporate security testing into release processes.
  • Review source code and provide secure coding guidance for remediation efforts.
  • Assess browser tokens, session management, caching, and authentication mechanisms.
  • Manipulate URLs, query parameters, browser data, and application workflows to identify exploitation opportunities.
  • Assist in incident response activities related to security vulnerabilities and published CVEs.
  • Create detailed reports outlining findings, risk levels, business impacts, and remediation recommendations.
  • Present security findings to both technical and non-technical stakeholders.
  • Contribute to security standards, policies, and secure development practices.
  • Stay current on emerging threats, attack techniques, and industry best practices.
  • Apply methodologies aligned with the MITRE ATT&CK Framework and OWASP guidelines.
Required Qualifications
  • Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related technical field.
  • Minimum of 6 years of software development and security experience.
  • Prior experience in a DevSecOps, Application Security, Security Engineering, or Penetration Testing role.
  • Strong hands-on Java development experience.
  • Experience supporting large-scale enterprise applications.
  • Knowledge of secure coding principles and application security best practices.
  • Experience performing penetration testing against web applications and services.
  • Strong understanding of OWASP Top 10 vulnerabilities and mitigation techniques.
  • Experience with security testing tools such as:
    • Burp Suite
    • Metasploit
    • Web Proxy Tools
    • Vulnerability Assessment Platforms
  • Experience using Static and Dynamic Application Security Testing tools, including:
    • Fortify on Demand (SAST)
    • Fortify on Demand (DAST)
  • Knowledge of common web vulnerabilities including:
    • SQL Injection
    • Cross-Site Scripting (XSS)
    • Authentication & Authorization Flaws
    • Session Management Vulnerabilities
    • API Security Risks
  • Strong understanding of cryptography and secure communications protocols (SSL/TLS).
  • Excellent analytical, troubleshooting, and problem-solving skills.
  • Strong written and verbal communication abilities.
  • Demonstrated professionalism, ethics, and confidentiality.
Preferred Qualifications
  • OSCP (Offensive Security Certified Professional)
  • GWAPT (GIAC Web Application Penetration Tester)
  • GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)
  • GPEN (GIAC Penetration Tester)
  • LPT (Licensed Penetration Tester)
  • CEH (Certified Ethical Hacker)
  • CISSP (Certified Information Systems Security Professional)
  • Experience with Python, Bash, or other scripting languages.
  • Experience performing secure code reviews for Java applications.
  • Knowledge of cloud security testing methodologies.
  • Mobile application penetration testing experience.
  • Experience conducting API security assessments.
  • Familiarity with HIPAA and regulated environments.
  • Knowledge of vulnerability management and CVE remediation processes.
Desired Technical Expertise
  • Java Security
  • Secure Coding Practices
  • Application Security
  • Penetration Testing
  • Vulnerability Assessments
  • OWASP
  • MITRE ATT&CK Framework
  • SAST/DAST
  • DevSecOps
  • Web Application Security
  • API Security Testing
  • Threat Modeling
  • Risk Assessment
Why Join Us?
  • Work on mission-critical enterprise applications.
  • Collaborate with a highly skilled cybersecurity team.
  • Influence secure development practices across large-scale environments.
  • Exposure to advanced security testing technologies and methodologies.
  • Opportunity to make a direct impact on application security and cyber resilience.

Apply today if you're passionate about offensive security, ethical hacking, and helping organizations build secure applications from the ground up.

 

Diversity creates a healthier atmosphere: MKS2 Technologies is proud to be an Equal Employment Opportunity / Affirmative Action employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Ethical Hacker / Penetration Tester in New York, NY vacancy
  • $174k - $252k

    Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.Drive the strategy for the teams core pillars by identifying emerging access risks and designing technical solutions to mitigate them at scale...
    Suggested

    Google

    New York, NY
    1 day ago
  • A digital product feedback company is seeking a Remote QA Review Assistant to test mobile apps and games. In this entry-level role, you'll install applications and evaluate their performance while providing valuable feedback. The position offers flexible hours with no ...
    Suggested
    Contract work
    Fixed term contract
    Remote work
    Flexible hours

    Review Pays

    New York, NY
    4 days ago
  • A leading gaming services company is looking for Community Game Testers to participate in paid, on-call test sessions. This flexible role allows you to test games from the comfort of your home using your own devices. Key responsibilities include evaluating user experience... 
    Suggested
    Remote job
    Extra income
    Flexible hours

    Keywords Studios

    New York, NY
    5 days ago
  • A premier health institution in New York is looking for a Sr. II Security Analyst specializing in vulnerabilities. This role involves conducting security assessments, analyzing security data, and coordinating remediation efforts. Candidates should have a Bachelor's degree...
    Suggested

    NYU Langone

    New York, NY
    2 days ago
  • Community Game Tester (Paid, On-Call) - US Get AI-powered advice on this job and more exclusive features. About GBTN GBTN is a community of gamers who help shape the future of video games. We partner with developers to test unreleased and in-development titles from the... 
    Suggested
    Extra income
    Full time
    Part time
    Immediate start
    Remote work
    Flexible hours

    Keywords Studios

    New York, NY
    5 days ago
  • $35 per hour

    A digital product testing company is seeking a Freelance Product Tester to review mobile apps and games. In this remote role, you'll install apps, evaluate their performance, and provide detailed feedback to enhance user experiences. This position allows for flexible hours... 
    Remote job
    Freelance
    Flexible hours

    Review Pays

    New York, NY
    5 days ago
  • $500 per month

    Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements: Must be 18 years... 
    Remote job
    10 hours per week

    Babki

    New York, NY
    2 days ago
  • $237.6k - $297k

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...
    Full time

    Scale AI

    New York, NY
    4 days ago
  • $180k - $215k

    The Senior Security Engineer, AI Security is a hands-on technical expert responsible for designing, implementing, and continuously enhancing the firm's AI Security Program. This role will serve as a key security partner to Application Security, Product Development, Technology...
    Visa sponsorship
    Work visa

    Simpson Thacher

    New York, NY
    15 hours ago
  • Working remotely, the full-time Senior Penetration Tester will independently conduct penetration testing of applications and systems, identify...  ...a certification in penetration testing, such as Certified Ethical Hacker (CEH) or Licensed Penetration Tester (LPT) Required to have... 
    Full time
    Remote work

    Virtual Vocations Inc

    New York, NY
    2 days ago
  •  ...primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, and...  ...peer reviews of penetration test reports and mentoring junior testers. ~ Continuous learner who keeps up with the latest offensive... 

    JPMorgan Chase & Co.

    New York, NY
    more than 2 months ago
  • A leading healthcare technology company is seeking a Director of IT & Security, CISO to oversee enterprise security and corporate IT. The ideal candidate will have over 10 years of IT experience, with strong expertise in securing AWS environments and leading security operations...
    Remote job

    Redox

    New York, NY
    1 day ago
  • MaziCTools is seeking a Game Tester to work from home. This role involves testing and providing feedback for upcoming games developed with the HyperScale Engine. Candidates should own a gaming PC and be available for online playtests during EU business hours. Ideal applicants... 
    Remote job
    Work from home

    MaziCTools

    New York, NY
    1 day ago
  • The Systems Manager, Vulnerability Management leads the Vulnerability Management team and drives measurable risk reduction across systems, Cloud, applications and operational technology (OT) and reports to the Director, Cybersecurity Operations while partnering closely...
    Shift work

    Con Edison Co.

    New York, NY
    19 hours ago
  • Digital Forensics Analyst We are seeking a detail-oriented and analytical Digital Forensics Analyst to investigate cyber incidents, collect and preserve digital evidence, and perform forensic analysis across computers, mobile devices, cloud platforms, and networks. ...

    Ova Technologies

    New York, NY
    2 days ago
  • Digital Forensic Analyst CGS is seeking a Digital Forensic Analyst whose primary focus will be on the preservation & collection of mobile device and cloud-stored data. This candidate should be fluent in a broad range of forensic technologies and interested in taking...
    Work at office
    Remote work
    Flexible hours

    Contact Government Services LLC

    New York, NY
    3 days ago
  •  ...landscape, committed to empowering organizations with our innovative solutions. POSITION: Part-Time Operational Technology (OT) Penetration Tester SUMMARY: IMRI is seeking a part-time OT Penetration Tester to support OT, ICS, SCADA, critical infrastructure, public-... 
    Part time
    For contractors
    Local area
    Remote work
    Monday to Friday
    Night shift

    IMRI Technology & Engineering Solutions

    New York, NY
    3 days ago
  • $105.4k - $207.8k

    Position Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking...
    Work experience placement
    Local area
    Remote work

    Deloitte

    New York, NY
    1 day ago
  • Job Description: Digital Forensics Specialist Position Title Digital Forensics Specialist Job Summary We are seeking a skilled Digital Forensics Specialist to conduct forensic investigations, collect and analyze digital evidence, and support...
    Full time
    Contract work

    Ova Technologies

    New York, NY
    2 days ago
  • Job Description Job Description Position Summary: This position requires a candidate that can commute to Long Island on a daily basis. Well established Manufacturing company, in business since 1951, is seeking a self motivated, team player, to focus on the following...

    Es Vee Placement

    New York, NY
    a month ago
  • $200k - $255k

     ...and AWS Shield) and explore third-party solutions to bolster our security posture. Assist in running and address findings from penetration tests and security audits, and ensuring prompt and effective remediation. Stay informed about the latest security threats, vulnerabilities... 
    Odd job
    Immediate start

    Cape

    New York, NY
    2 days ago
  •  ...issues - Support secure development practices for in-house applications - Assist with annual security assessments, including: - Penetration Testing - Vulnerability Assessment - IT Risk Assessment Requirements - Must be authorized to work in U.S. -... 

    Cesna Recruitment

    New York, NY
    a month ago
  • $173.9k - $290.1k

    Job ID: 1437169533Location: New York, NY, US, 10001-8604Salary: $173,900 - $290,100Job Function: Technology ConsultingEmployer: EY Global ServicesApply by: 2026-10-20Company: EYLocation: Anywhere in CountryAt EY, we’re all in to shape your future with confidence. We’ll ...
    Immediate start

    EY (Ernst & Young)

    New York, NY
    2 days ago
  •  ...engineer to continuously attack, test, and strengthen their AI product and infrastructure. This person should think like a white-hat hacker: spend meaningful time trying to break the system, identify vulnerabilities across agents, APIs, identity, memory, permissions,... 
    Remote work

    Truelogic

    New York, NY
    2 days ago
  • Beyond Identity is revolutionizing digital access for organizations looking to improve protection against cyber attacks. The Chief Information Security Officer (CISO) will oversee the strategic planning and implementation of cybersecurity programs, ensuring alignment...
    H1b
    Remote work

    Jobright.ai

    New York, NY
    4 days ago
  • $250k

    The New York, NY office of Lewis Brisbois, a full-service AmLaw 100 firm, is seeking a Chief Information Security Officer. The Chief Information Security Officer (CISO) is a senior executive responsible for developing, implementing, and overseeing a comprehensive, enterprise...
    Work at office

    Lewis Brisbois

    New York, NY
    5 hours ago
  • $350k - $400k

     ...Trust adoption, identity and access management, and secure data handling practices across both organizations. Oversee regular penetration testing, vulnerability assessments, and third-party risk management. Team Leadership & Development Lead and foster collaboration... 
    Contract work
    Local area
    Shift work

    The Security Executive Council

    New York, NY
    5 hours ago
  • $300k - $350k

     ...with Engineering leadership to embed security into the product development lifecycle. Lead teams conducting threat modeling, penetration testing, red-teaming, and incident response programs. Set and communicate security policy to the board and executive team, translating... 
    Odd job
    Work at office
    Immediate start
    Relocation package

    Cape

    New York, NY
    2 days ago
  • $350k - $400k

    Overview At Compass, our mission is to help everyone find their place in the world. Founded in 2012, we’re revolutionizing the real estate industry with our end-to-end platform that empowers residential real estate agents to deliver exceptional service to seller and...
    Flexible hours

    The Security Executive Council

    New York, NY
    1 day ago
  • $250k - $325k

    About The Company Rain is the global stablecoin payments platform for enterprises, neobanks, platforms, developers, and AI agents. Our technology allows partners to move, store, and use stablecoins instantly and compliantly through global payment cards, rewards, on/...
    Work at office
    Work from home
    Worldwide
    Flexible hours

    Rain

    New York, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Ethical Hacker / Penetration Tester. Be the first to apply!