Senior Application Penetration Tester
Chubb
Penetration Tester
Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native/containerized, and AI/LLM-integrated applications.
Assess AI/ML and generative AI-powered features for risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure, aligned to the OWASP Top 10 for LLM Applications and MITRE ATLAS.
Partner with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelines.
Evaluate cloud-native and containerized workloads (AWS, Azure, GCP, Docker, Kubernetes) and Infrastructure as Code for misconfigurations and weak security controls.
Test modern API architectures (REST, GraphQL, gRPC), including OAuth2, OIDC, and JWT authentication and authorization flaws, and microservices-based applications.
Conduct mobile application security testing and reverse engineering, including hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypass.
Own the overall vulnerability remediation status of the global application portfolio, and serve as the primary point of contact for application teams on remediation matters.
Manage application risk rating processes and ensure timely risk scoring of new and changing applications.
Build and maintain dashboards and status reports for portfolio leads and CIOs, and follow up on overdue vulnerabilities to meet compliance timelines.
Develop clear, actionable penetration test reports and communicate findings and remediation strategy to both technical and executive stakeholders.
Research emerging attack techniques and tooling, and drive automation and process improvements across the testing program.
Qualifications
Minimum:
- Prior experience managing Information Security projects
- Bachelor's Degree in Computer Science, Engineering, or other Engineering or Technical discipline, or equivalent relevant experience
- Minimum of 2 years' professional experience performing web application, API endpoint, and mobile (iOS & Android) penetration testing
- Knowledge of prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets
- Knowledge of industry standards regarding vulnerability management, including Common Vulnerabilities and Exposures (CVE) and Common Vulnerability Scoring System (CVSS)
- Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening and security baselines, and web server and database security
- Knowledge of penetration testing principles, tools, and techniques
- Working experience with industry frameworks (OWASP, OWASP API Security Top 10, OWASP Top 10 for Large Language Model (LLM) Applications, NIST, NIST AI Risk Management Framework, MITRE ATT&CK, etc.)
- Comfortable working outside their comfort zone with a willingness to learn
- Excellent verbal and written communication skills
- Strong analytical skills
- Strong team player with the ability to work independently
- Strong project management skills and ability to multi-task
- Self-motivated with strong initiative
- Knowledge of computer networking concepts and protocols, and application security methodologies
- Skill in performing impact/risk assessments
- Familiarity with modern application architectures, including cloud-native (AWS, Azure, GCP), containerized (Docker, Kubernetes), microservices, and API-first (REST, GraphQL, gRPC) designs
- Foundational understanding of AI/ML and generative AI security risks (e.g., prompt injection, model manipulation, sensitive data leakage) is a plus
Nice To Have:
- Strong understanding of secure SDLC, exploit/attack techniques, and core networking, application, and OS concepts, with the ability to manipulate application logic, bypass security controls, and develop exploits
- Experience scoping and leading engagements end-to-end — from kickoff through remediation tracking — and improving testing efficiency through automation, tooling, and process improvements
- Proficient with industry-standard tools across categories: Kali Linux, Metasploit, Nmap, Burp Suite/OWASP ZAP (web); Santoku, Genymotion, APKTool, JD-GUI (mobile); SQLMap, Semgrep, Snyk, Checkmarx/AppScan/Veracode (code); Postman/Insomnia (API); Trivy/Grype, Prowler/ScoutSuite (cloud & containers); and Garak/PyRIT (AI red-teaming)
- Skilled in identifying OWASP Top 10 (Web & Mobile), OWASP API Security Top 10, and OWASP LLM Top 10 vulnerabilities, and developing secure coding checklists based on OWASP ASVS
- Experience conducting full-scope assessments and penetration tests — web, mobile, API, social engineering, and server/client-side attacks — including mobile reverse engineering (hardcoded credentials, SQLi, keychain exposure, anti-emulator/obfuscation bypass)
- Experience assessing cloud-native and containerized applications (AWS, Azure, GCP, Docker, Kubernetes), modern CI/CD pipelines and Infrastructure as Code, and modern API architectures (REST, GraphQL, gRPC) including OAuth2/OIDC/JWT flaws
- Experience or working knowledge testing AI/ML and generative AI features for risks such as prompt injection, insecure output handling, training data poisoning, and sensitive data disclosure, aligned to the OWASP LLM Top 10 and MITRE ATLAS, plus working knowledge of securing AI agent/orchestration frameworks (LangChain, Semantic Kernel, AutoGen) and RAG vector databases
- Skilled in code analysis, exploit development, and using attacker tools/tactics/procedures to identify, validate, and demonstrate vulnerabilities an adversary could exploit
- Ability to analyze findings (including root cause analysis), risk-rate vulnerabilities by actual business impact, and prioritize key risk areas
- Ability to document findings clearly, including reproduction steps, and produce comprehensive, accurate penetration test reports
- Ability to research and recommend practical short- and long-term remediations, and communicate findings and strategy effectively to both technical and executive stakeholders
- Experience working closely with development teams to track remediation through to production deployment, maintain vulnerability status dashboards, and follow up on overdue items to meet compliance timelines
- Preferred certifications: OSCP, OSWE, GWAPT, GPEN, CEH, GCPN, CCSP, or equivalent AI/ML security credentials
- Strong communicator and collaborative team player, able to adapt and reprioritize as project needs shift
About Us
Chubb is a world leader in insurance. With operations in 54 countries, Chubb provides commercial and personal property and casualty insurance, personal accident and supplemental health insurance, reinsurance, and life insurance to a diverse group of clients. The company is distinguished by its extensive product and service offerings, broad distribution capabilities, exceptional financial strength, underwriting excellence, superior claims handling expertise and local operations globally. At Chubb, we are committed to equal employment opportunity and compliance with all laws and regulations pertaining to it. Our policy is to provide employment, training, compensation, promotion, and other conditions or opportunities of employment, without regard to race, color, religious creed, sex, gender, gender identity, gender expression, sexual orientation, marital status, national origin, ancestry, mental and physical disability, medical condition, genetic information, military and veteran status, age, and pregnancy or any other characteristic protected by law. Performance and qualifications are the only basis upon which we hire, assign, promote, compensate, develop and retain employees. Chubb prohibits all unlawful discrimination, harassment and retaliation against any individual who reports discrimination or harassment.
Job Info
- Job Identification 36116
- Job Schedule Full time
- Regular or Temporary Regular
- Job Category Security Engineering
- Business Unit United States
- Legal Employer ACE American Insurance Company
- ...manage to secure success.We are seeking a skilled Penetration Tester to assess the security of web applications, APIs, and related systems. This role is responsible... ...development From entry-level employees to senior leaders, we believe there’s always room to learn....SeniorWork at officeLocal areaRelocationNight shift
$105.4k - $207.8k
Position Summary Senior Consultant - Technology Resilience Accelerate your career as a Senior Consultant, Technical Resilience... ...Bachelor's degree 4 years of experience in infrastructure or application architecture, with hands-on exposure to both on-premise and...SeniorLocal areaVisa sponsorship$105.4k - $207.8k
...Summary Join Deloitte’s Cyber practice as a Cyber SecOps Senior Consultant and help clients navigate an evolving threat... ...of log ingestion pipelines using data fabric technologies and application programming interface integrations, including Bindplane and cloud...SeniorLocal areaVisa sponsorship$97.61k - $188.38k
...doAs Identity and Access Management (IAM) solutions team Saviynt Senior Consultant, you will:Demonstrate advanced understanding of... ...and access governance software into clients' infrastructure and applications.2+ years of experience with installation, integration, and...SeniorLocal areaVisa sponsorship$105.4k - $207.8k
Position Summary As a Senior Consultant - Cyber Defense and Resilience, you will help deliver security engineering solutions that... .... The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which...SeniorLocal areaVisa sponsorship$105.4k - $207.8k
Position Summary Cyber Senior Consultant - DevSecOps Position Summary Are you interested in working in a dynamic environment... ...implementation plans.Design and implement Secure-by-Design and Application Security processes across the software development lifecycle,...SeniorLocal areaWorldwideVisa sponsorship$105.4k - $207.8k
Position Summary As a Full Stack Engineer Senior Consultant in Deloitte Cyber’s Digital Trust & Privacy practice, you will... ...generative AI (GenAI)-enabled capabilities where applicableBuilding application programming interfaces (APIs), automations, workflows,...SeniorLocal areaVisa sponsorship- ...clearly state that you have an active DoD Secret security clearance, auto-filtering tools will reject/remove your application. EXPERIENCE for Senior Security Network Engineer position: Eight (8) years’ experience in network security, demonstrating strong experience...Senior
$141.92k - $212.89k
...forefront of cybersecurity resilience in the financial sector? As a Senior Principal Risk Specialist, Cyber Engagements, you'll play a... ...$248,700To be considered for this position, please submit an application. Applications are accepted on an ongoing basis.The information...SeniorFull timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start- ...Senior Systems Analyst Employment Type: Full Time, Senior-level Department: Information Technology CGS is seeking a Senior... ...office automation networks, and PC and server-based databases and applications. Experience in a litigation support environment is...SeniorFull timeContract workFor contractorsWork at officeFlexible hours
$117.17k - $175.76k
...the selected candidate base pay within this range, dependent on job-related, non-discriminatory factors such as experience. The application window is 30 days from the date job is posted, unless the number of applicants requires it to close sooner or later.Base pay is one...SeniorFull timeWork at officeRemote workWorldwide$134.5k - $265.1k
...Recruiting for this role ends on 12/31/2026.Work you'll doAs a Senior Engineering Management Specialist on the Cyber Defense &... ...overseeing patching across Windows, Linux, middleware, endpoints, or applications using tools such as BigFix, Microsoft Endpoint Configuration...SeniorLocal area- A healthcare staffing firm is seeking a Senior Analyst to support the Midas application within an acute care environment. The role includes system implementation, user training, and resolving customer support tickets. Candidates must have a background in Clinical Information...Senior
$105.4k - $207.8k
...Recruiting for this role ends on 12/31/2026. Work you'll do As a Senior Consultant, Sentinel on the Deloitte Cyber team, you will be... ...development, and third-party or software-as-a-service application connectivityCreating technical reports, security visualizations...SeniorLocal areaVisa sponsorship- ...ensure the delivery of quality software applications. Involved in test planning, writing test... ...diverse pool of Quality Assurance contract testers who can help keep up with testing these... ...: Information TechnologyExperience level: Mid-Senior LevelIndustry: TelecommunicationsContract workWork experience placementImmediate start
- ...Senior Director, Principal Gifts About the Company Philanthropic organization supporting Indigenous culture & individuals Industry... ...the organization at various events and gatherings. Applicants for this role at the company should have a deep commitment to Indigenous...Senior
- ...Cencora is seeking a senior cloud architect to define and govern enterprise solution architectures across Microsoft Azure and AWS. You will lead cloud modernization initiatives, apply healthcare technology expertise, and guide architecture decisions with a product ownership...Senior
$163.4k - $322.1k
Position Summary Deloitte is seeking an AWS Cloud Security Senior Manager to lead the design and delivery of cloud security... ...development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected...SeniorLocal areaVisa sponsorship$105.4k - $207.8k
...Recruiting for this role ends on 12/31/2026.Work you'll doAs a Senior Engineering Management Specialist on the Deloitte Cyber... ...governance, provisioning, certification, role management, and application onboardingCollaborating with client stakeholders, product owners...SeniorLocal areaVisa sponsorship$163.4k - $322.1k
Position Summary Cyber Security Architecture Senior Manager - Strategy, Growth and Transformation Deloitte is seeking a Senior... ...stakeholders on security strategy, architecture, cloud and application security, and operating model decisions while leading teams that...SeniorLocal areaVisa sponsorship$163.4k - $322.1k
Position Summary Deloitte is seeking a Senior Manager to lead how clients secure their Google Cloud Platform (GCP) cloud and... ...and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected...SeniorLocal areaVisa sponsorship- ...CapTech cannot transfer nor sponsor a work visa for this position. Applicants must be authorized to work directly for any employer in the... ...without visa sponsorship. SummaryType: Full-timeFunction: ConsultingExperience level: Mid-Senior LevelIndustry: Management ConsultingSeniorWork at officeRemote workVisa sponsorshipWork visaFlexible hours
$155.6k - $306.8k
...026. Key job responsibilities include: Guidance and Support to Senior Business Leaders within the Firm Serves as liaison between firm... ...early coordination with Office of General Counsel on RFPs where applicable. Contract Negotiation for Cyber Services Involved in the...SeniorContract workFor subcontractorWork at officeLocal area$77k - $202k
...development and implementation of cloud security strategies. As a Senior Associate, you will analyze complex problems, mentor junior... ...individual's skills, experience, qualifications and location, and applicable employment laws. All hired individuals are eligible for an...SeniorFull timeH1b$134.5k - $265.1k
...technical solutions (including AI/GenAI-enabled capabilities where applicable), and deploy them for clients in alignment with their... ...feasibility and business goals.5+ Years experience working with senior client stakeholders to translate requirements into scalable technical...SeniorLocal areaVisa sponsorship$134.5k - $265.1k
Position Summary As a Senior Consultant in Deloitte Cyber’s Digital Trust & Privacy practice, you will help clients solve complex... ...needs across Identity Governance and Administration, Web and Application Programming Interface Access Management, Privileged Access...SeniorLocal areaVisa sponsorship- Role Summary FP Movement is seeking a Senior Digital Project Manager to lead the delivery of complex, cross-functional initiatives... ...provide equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, sex (including...SeniorFull timeFlexible hours
$168k - $240k
...impactful work and the evolution of Slalom.The Role: M&A Principal/Senior PrincipalWhat You’ll Do:* Delivery areas include:* Executing... ...time. We are committed to pay transparency and compliance with applicable laws. If you have questions or concerns about the pay range or...SeniorTemporary workWork at officeLocal areaImmediate start$105.4k - $207.8k
Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business... ...and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected...SeniorWork experience placementLocal areaVisa sponsorship$25 per hour
Description: RLDG is hiring remote, part-time independent contractors in Pennsylvania, Michigan, and West Virginia. You'll test online games and digital experiences by following set steps, then record and report what you find. It's flexible online work you fit around...Hourly payPart timeFor contractorsRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Penetration Tester. Be the first to apply!
- srs distribution Philadelphia, PA
- senior associate architect Philadelphia, PA
- senior dynamics crm developer Philadelphia, PA
- senior application security Philadelphia, PA
- senior account director Philadelphia, PA
- senior plumbing designer Philadelphia, PA
- senior sales representative Philadelphia, PA
- senior advisor Philadelphia, PA
- senior cloud data engineer Philadelphia, PA
- senior customer service manager Philadelphia, PA



