Penetration Tester (JAVA) Job at Kanak Elite Services Inc, Albany, NY

UFl5TmxDQTlRNk1RQVNEdnJUcVJqZDhLa0E9PQ==
  • Kanak Elite Services Inc
  • Albany, NY

Job Description

This is a C2C Position

Duration: On Going

Location: On Site Albany, NY Hybrid 4 days per month onsite and onsite if needed for meetings or other circumstances.

Job Brief:

A Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats.

Basic Minimum Experience.

Bachelor's degree in a related software field with 6+ years in a Dev Sec role.

Core Java coding experience.

Previous job background as an engineer and Dev Sec position on a large-scale public enterprise scale application.

Key Responsibilities:

  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Collaborate with Development teams to understand application architecture and find security weaknesses early.
  • Collaborate with Testing teams to integrate with manual and automation testing.
  • Provide guidance on secure coding and how to fix vulnerabilities.
  • Stay updated on Java security threats and best practices.
  • Help improve secure development processes (SDLC).
  • Assist in responding to security incidents related to Java vulnerabilities, current published NIST CVE.
  • Clearly document and report findings, including technical details, risk assessment, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Contribute to security policies for Java development and deployment.
  • Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses' browser tokens and cache manipulation and Production vs. none prod architecture.
  • Familiar with MITRE ATT&CK Framework.

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Minimum of 6 years of Development/Security experience
  • Experience in Penetration Testing/Ethical Hacking with a focus on Java application security.
  • Strong knowledge of Java programming and its security practices as well as scripting experience.
  • Proficiency in web application security principles (e.g., OWASP).
  • Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques.
  • Experience with penetration testing tools like Burp Suite, Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
  • Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.

Preferred Qualifications:

  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.
  • Experience with scripting languages (e.g., Python, Bash).
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations like HIPAA.
  • Experience with API testing

Feel free to reach me at gauravverma@kanakits.com

Job Tags

Similar Jobs

Nesco Resource

Junior Lab Tech Job at Nesco Resource

 ...Junior Lab Tech Nesco Resource is searching for an entry level junior lab technician to join one of the largest O&G Analysis companies...  ...a MEC (Minimum Essential Coverage) plan that encompasses Medical, Vision, Dental, 401K, and EAP (Employee Assistance Program) services... 

Diverse Lynx

Python/Hadoop Developer Job at Diverse Lynx

Role : Python/Hadoop DeveloperLocation : Pennington, NJ / Charlotte, NC (Onsite)Duration : Full time + Benefits + Bonus.Job DescriptionCandidate should possess strong Test automation skills in Python for data validation.Need experience in any of the ETL tools.... 

UBS

KYC Reviews Analyst Job at UBS

 ...Client Lifecycle Services for the Investment Bank. This is a front office / client facing role responsible for gathering and analyzing KYC information; enabling an efficient and transparent KYC review experience for our institutional clients. The ideal candidate will... 

Summit Recruiting Group LLC

Sleep Medicine Physician Job at Summit Recruiting Group LLC

 ...Sleep Medicine Opening in State College, PA Area is surrounded by state parksLocated 140 miles from Pittsburgh; 170 miles from Baltimore...  ...Exciting opportunity for a Sleep Fellowship, BC/BE sleep medicine physician to join our multi-specialty group ~ Currently staffed by a... 

Maximus Health, Inc.

Care Coordinator (Remote) Job at Maximus Health, Inc.

 ...Job Description Job Description Position is Remote (US/Canada) No agencies please Company Overview Maximus ( is a...  ...Stoic, & Shopify. Position Summary In this role as a Care Coordinator supporting Maximus patients, you will be instrumental in delivering...