Penetration Tester (Atlanta) Job at Stefanini North America and APAC, Atlanta, GA

S29Fb3luQ2JpS0NlMWpRU1p0YlJ5bmU2c3c9PQ==
  • Stefanini North America and APAC
  • Atlanta, GA

Job Description

Position Summary

As a key member of our Internal Product Security Engineering team, you will lead penetration-testing engagements for high-scale web applications and APIs, validating security controls and uncovering exploitable weaknesses. In parallel, you will conduct structured threat-modeling workshops and security-design reviews for new features and services, managing each engagement from scoping to remediation follow-up in close partnership with engineering and cross-functional stakeholders. The insights you provide will drive prompt fixes and shape the organization's long-term security roadmap.

Key Responsibilities

  • Penetration Testing
  • Plan, execute, and document manual and tool-assisted tests for enterprise-scale web apps and REST/GraphQL/gRPC APIs.
  • Demonstrate exploitation paths (auth / logic / data exposure) and develop proofs-of-concept.
  • Retest remediations and deliver clear, prioritized reports.
  • Threat Modeling & Security Design Review
  • Facilitate formal and informal Threat Modeling using STRIDE-like frameworks or Attack-Tree sessions for new or significantly modified services.
  • Produce risk artefacts, recommend mitigations, and track closure of findings.
  • Security Engineering & Advocacy
  • Champion secure-by-default patterns (least privilege, IaC hardening, SDL best practices) across the SDLC.
  • Contribute to internal security tooling and CI/CD guardrails.

Requirements:

  • Bachelors degree in Computer Science, Engineering, or equivalent practical experience.
  • 4 + years in product or application security engineering with hands-on web/API penetration-testing work.
  • Expertise with a leading pentest platform (Burp Suite Pro, OWASP ZAP, Nuclei, etc.).
  • Scripting/automation ability in Python, Go, or similar; quick at reading unfamiliar codebases.
  • Practical experience with STRIDE or comparable threat-model frameworks.
  • Familiarity with cloud-native environments (microservices, Kubernetes, serverless).
  • Communication: Exceptional written and verbal skills for both technical and non-technical audiences.

Preferred Qualifications

  • Offensive-security certifications (OSCP, OSWE, OSWA, BSCP).
  • Secure-coding experience in languages such as: Java, Node.js, C#, Python, or Rust.
  • Experience in security controls for cloud platforms such as AWS, Azure, or Google Cloud.
  • Open-source contributions, bug-bounty recognitions, or CTF placements.
  • Exposure to mobile or desktop application security.
  • Knowledge of or interest in AI security controls and testing.

Personal Attributes

  • Maintains professionalism under pressure.
  • Meticulous eye for detail.
  • Self-driven and proactive.
  • Thrives on complex challenges.
  • Dependable, cooperative team player.

Job Tags

Part time,

Similar Jobs

Metalcraft of Mayville

Assembler - 1st Shift (Mayville) Job at Metalcraft of Mayville

 ...disabilities/sexual orientation/gender identity Assembler - 1st Shift (Mayville) US-WI-Mayville...  ...Manager, Assemblers are responsible for working direclty with team members, as well as,...  ...Facility Advancement Opportunities Free Health Clinic On-the-job training... 

Guidehouse

Workday HCM Optimization Senior Consultant (Hiring Immediately) Job at Guidehouse

 ...From initial assessments to entire transformations, you'll deliver Workday solutions to equip organizations with the information they need to optimize their Workday environments. As a Workday HCM Optimization Manage rat Guidehouse, you will: Manage in the Optimization... 

Online Remote Jobs

Data Entry Specialist Job at Online Remote Jobs

 ...About the job Data Entry Specialist NOTE: Only US citizens will apply. We are looking for a Data Entry Clerk to type information into our database from paper documents. The ideal candidate will be computer savvy and a fast typist with a keen eye... 

Remote Career

Remote Data Entry Operator Job at Remote Career

 ...About the job Remote Data Entry Operator Job Description Data Entry Operator Responsibilities: Gathering, collating,...  ...experience as a data entry operator or similar. ~ Excellent typing abilities. ~ Excellent time management and multitasking abilities... 

Global Cosmetics Company

Model wanted (experienced or non-experience are welcome) Job at Global Cosmetics Company

Model wanted (experienced or non-experience are welcome)Model wanted for global cosmetics company. Your picture will be used for posters and fasion magazines.Ladies perfered. And please send your pics to Email: ***@***.*** ,more than one pic is preferd.Or you can contact...