Himalayas logo
SIXGENSI

Senior Web Application Penetration Tester

SIXGEN is a veteran-founded cybersecurity company dedicated to enhancing national security through innovative cyber solutions.

SIXGEN

Employee count: 51-200

Salary: 100k-145k USD

United States only

SIXGEN’s mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and cutting-edge capabilities to uncover vulnerabilities, protect vital systems, and ensure operational superiority in an ever-evolving digital landscape.

POSITION OVERVIEW

  • Position: Senior Web Application Penetration Tester
  • Job Type: Full Time
  • Location: Remote US. Proximity to Maryland or Virginia is a plus, but not required
  • Clearance Requirements: Ability to obtain a Secret Clearance
  • Travel: Up to 10%

ABOUT THE TEAM

SIXGEN supports cyber and intelligence missions by serving government and commercial organizations as they overcome global cybersecurity challenges. You’ll work with our highly skilled operators conducting research and assessments based on real-world threats. You’ll simulate adversaries and malicious actors and report details and actionable findings on critical assets and infrastructures. Using innovative processes, tools, and techniques, you’ll predict and overcome cybersecurity vulnerabilities. Your successes will be supported by our diverse team of experienced, technical talent.

WHAT YOU'LL DO

  • Conduct comprehensive, black-box penetration testing of web applications to identify critical vulnerabilities such as SQL injection, XSS, CSRF, XXE, deserialization attacks, RCE, etc. Utilize a bug bounty-style approach to independently enumerate and assess targets, simulating real-world attack scenarios.
  • Analyze application architecture and source code (when available) to uncover deeper, logic-based or systemic vulnerabilities.
  • Document and communicate findings with clear risk assessments, reproduction steps, and actionable remediation recommendations.
  • Stay up to date with evolving web technologies, threat trends, and security tools to ensure cutting-edge testing practices.

REQUIRED QUALIFICATIONS

  • US Citizen with the ability to obtain a Secret clearance.
  • Minimum 5 years of hands-on web application penetration testing experience, with a strong preference for OSCP or equivalent hands-on certifications (e.g. CBBH, CWEE, OSWA, OSWE, GWAPT).
  • Proven ability to conduct full-scope penetration tests using tools like Burp Suite, Kali Linux, Metasploit, Nuclei, Nessus, and Nmap.
  • Experience developing actionable intelligence based on open source intelligence (OSINT) gathering.
  • Experience building offensive capabilities or tools to enhance operations with programming languages such as, but not limited to, Python, Bash, terraform, ansible, etc.
  • Experience in testing web-based APIs (i.e. REST, SOAP, XML, JSON).
  • Advanced knowledge of manual testing techniques and automated tools (e.g., Burp Suite, OWASP ZAP) to assess application security.
  • Familiarity with FISMA and NIST 800-series frameworks; experienced in applying formal testing protocols and methodologies to assess networks, web apps, and cloud environments.
  • Strong communication skills for interfacing with clients and documenting findings
  • Demonstrated experience working both collaboratively and independently with minimal supervision.
  • Awarded CVEs, Cloud, and Active Directory penetration testing is a plus but not required.

COMPENSATION BENEFITS

Salary Range: $100,000 - $145,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role.

Additionally, SIXGEN offers top-tier benefits for full-time employees, including:

  • Employer-paid health insurance premiums (medical, dental, vision) for you and your family
  • Employer-paid short/long term disability insurance and basic life/ADD insurance
  • 401K with a 4% employer contribution
  • Professional development reimbursement options available (training, certification, education, etc)​
  • Flexible and remote work policies for most positions
  • Flexible PTO and holiday schedule

OUR COMMITMENT

SIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.

We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Salary

Salary: 100k-145k USD

Location requirements

Hiring timezones

United States +/- 0 hours

About SIXGEN

Learn more about SIXGEN and their company culture.

View company profile

SIXGEN is a veteran-founded cybersecurity company dedicated to enhancing national security through innovative cyber solutions. Our mission is to provide world-class cybersecurity services that empower military, government, and commercial organizations to protect critical infrastructure against evolving cyber threats. We utilize state-of-the-art technologies combined with a talented team of experts who bring extensive experience from various sectors, including military and intelligence.

Our services range from threat emulation and penetration testing to comprehensive red teaming and CMMC compliance support. By integrating advanced techniques and methodologies, we ensure that our clients are equipped to not only defend against adversaries but also maintain operational efficiency and resilience. Our approach is built on the principles of honor, integrity, and a strong commitment to ethical practices in cybersecurity.

Claim this profileSIXGEN logoSI

SIXGEN

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

2 remote jobs at SIXGEN

Explore the variety of open remote roles at SIXGEN, offering flexible work options across multiple disciplines and skill levels.

View all jobs at SIXGEN

Remote companies like SIXGEN

Find your next opportunity by exploring profiles of companies that are similar to SIXGEN. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan