NetSPI logo

Principal Security Consultant (Web Application Penetration Tester)

NetSPI
Full-time
Remote
Worldwide

JobsCloseBy Editorial Insights

NetSPI is seeking a Principal Security Consultant focused on web application penetration testing to work remotely from the United Kingdom. You will lead web apps and API engagements, deliver reports, mentor teammates, and advance NetSPI’s PTaaS capabilities across teams. Expect travel and an 8 hour day with occasional evenings or weekends to meet deadlines. Requirements: 5+ years in penetration testing, strong OWASP Top 10 and MITRE ATT&CK knowledge, proficiency with Kali, Burp Suite, Metasploit, Nessus, and Windows Linux MacOS internals, plus scripting in Ruby Python Java or C#. Apply by highlighting web app and API pentesting wins, client-facing reporting, leadership, and outcomes; include links to blogs or talks and demonstrate communication.


NetSPI® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts. Specializing in 50+ pentest types, attack surface visibility, vulnerability prioritization, and attack simulation, NetSPI delivers security testing with unprecedented clarity, speed, and scale.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at www.netspi.com/careers.

Join the mission as a Principal Security Consultant. We are seeking a skilled and detail-oriented Penetration Tester to conduct thorough security assessments, identify vulnerabilities, and provide expert recommendations to strengthen our clients' security posture. As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.

Responsibilities:

  • Conduct engagements on web applications and underlying APIs independently and provide technical oversight
  • Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture.
  • Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes
  • Offer mentorship or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
  • Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations.
  • Lead collaboration with cross-functional teams on key activities, including scoping engagements, serving as a subject matter expert in customer-facing sales meetings, and contributing to marketing campaigns.

Minimum Qualifications:

  • Bachelor’s degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience
  • 5+ years of work experience in Penetration Testing
  • Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus)
  • Familiarity with offensive and defensive IT concepts and protocols
  • Extensive understanding of the OWASP Top 10, MITRE ATT&CK framework, and various security frameworks
  • Working knowledge of Windows, Linux and MacOS operating systems internals
  • Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
  • Ability to work independently and as part of a team
  • Proficient communication skills, both written and verbal
  • Willingness to travel up to 5-10%
  • This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs

Preferred Qualifications: 

  • Conduct engagements independently on both web application and thick client applications, while providing technical oversight for our web application offering
  • Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)
  • Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, GWAPT)

 

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.