Application Security Penetration Tester – Hybrid – Contract-to-Hire
A large financial services organization is seeking an Application Security Penetration Tester for a hybrid, contract-to-hire position. This role supports the organization’s Technology Risk initiative by delivering offensive security assessments and guiding secure development across key projects.
Join our Application Security team as part of our broader Technology Risk initiative. As an Application Security Penetration Tester, you’ll lead offensive security assessments, perform hands-on testing of applications and APIs, and provide expert guidance on key projects. Your goal: identify vulnerabilities before attackers do, and help build more secure software across the enterprise.
Key Responsibilities
- Conduct offensive security testing on applications, APIs, and services.
- Perform targeted threat hunting to identify potential risks in application environments.
- Execute manual penetration testing beyond standard automated scans.
- Document and communicate vulnerabilities using a defined reporting format.
- Summarize assessment findings and support remediation efforts.
- Provide subject matter expertise on secure application design and defensive techniques.
- Collaborate with Security Architects, Product Managers, and Risk teams to ensure secure delivery across products.
What You’ll Bring
-
6+ years of experience testing web applications for security vulnerabilities.
-
4+ years of hands-on experience with tools such as Burp Suite, OWASP ZAP, or similar.
- Strong manual testing skills and the ability to identify OWASP Top 10 issues without relying on scanners.
- Familiarity with adversarial methodologies and the MITRE ATT&CK Framework.
- A Bachelor’s degree or equivalent experience.
- Strong communication skills and the ability to work across multiple teams and priorities.
Bonus Skills (Nice to Have)
- Exposure to penetration testing or red teaming methodologies.
- Participation in Capture The Flag (CTF) events or hands-on training platforms like TryHackMe or HackTheBox.
- Experience completing advanced security courses or labs.
- Interest in continuous learning and staying current on security trends.
Note: Certifications (e.g., OSCP, OSWE, GPEN) are appreciated but not required.
Why Join Us?
You'll work in a collaborative, security-focused environment where your skills directly impact the safety and integrity of critical applications. If you're passionate about offensive security and enjoy digging deep into real-world risks, we’d love to hear from you.
Flexible work from home options available.
Our History
Years ago, SynergisticIT founders Carlos Pinzon and Antonio Proto recognized a significant gap in IT consulting and staffing services. On the one hand there are thousands of staffing firms who overload their clients with resumes that do not come close to meeting client needs. Alternatives—such as global consulting firms with costly layers of bureaucracy—achieve great results, but at a very high price.
In response, Carlos and Antonio built a new type of IT staffing company where technical recruiters—all experienced IT professionals—match IT resources to our client’s exact job requirements, providing superior talent at a lower cost and far lower risk.
Our Mission
SynergisticIT’s mission is to match great companies with great talent, serving our clients with professionalism, honesty and integrity.
Our Vision
To be the number one choice of Fortune 1000 companies seeking critical IT talent.
If you are an IT professional who is passionate about IT, join us!
SynergisticIT has been providing leading Fortune 1000 companies and government agencies with top IT talent for over 25 years. Our firm is led by IT professionals so we understand you, respect your talent, and recognize the value you can provide to our clients.
Whether you are seeking a consultant or a full time employee position, we will find a match for you with one of our premier clients. Unlike many other consulting firms, SynergisticIT will prepare you for the interview and support you throughout your consulting engagement.