Job Title: Principal Ethical Hacker / Penetration Tester
Client: Deloitte
Employment Type: W2 Contract
Location: Albany, NY Hybrid
Travel: Required to travel to Albany, NY twice per month
Deloitte is seeking a highly skilled Principal Ethical Hacker / Penetration Tester with strong expertise in Java application security, penetration testing, secure coding, and DevSecOps . The ideal candidate will identify, exploit, assess, and help remediate vulnerabilities in enterprise-scale Java applications and infrastructure.
Required QualificationsBachelor's degree in Computer Science, Information Security, or related field
6+ years of software development and/or security experience
Strong Core Java programming experience
Experience with penetration testing and ethical hacking
Experience securing large-scale enterprise Java applications
Strong knowledge of application security and OWASP
Experience identifying SQL Injection, XSS, authentication, authorization, and other web vulnerabilities
Hands-on experience with Burp Suite and Metasploit
Experience with SAST/DAST tools, preferably Fortify on Demand
Strong understanding of cryptography and SSL/TLS
Experience with secure code review
Scripting experience with Python and/or Bash
Conduct penetration tests and vulnerability assessments for Java applications and infrastructure
Identify security vulnerabilities through automated and manual testing
Develop and use custom exploits to simulate attacker techniques
Perform secure code reviews of Java applications
Collaborate with development teams to identify security weaknesses early in the SDLC
Work with testing teams to integrate security testing with manual and automated testing
Provide secure coding guidance and remediation recommendations
Monitor emerging Java security threats and vulnerabilities
Review published CVEs and NIST security advisories
Assess URLs, query parameters, browser tokens, cache mechanisms, and application data for attack vectors
Evaluate production and non-production architectures
Document security findings, risk assessments, and recommended remediation
Communicate findings to technical and non-technical stakeholders
Contribute to secure development policies and processes
OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or similar certification
Java secure code review experience
API security testing
Cloud security testing
Mobile application penetration testing
HIPAA/security compliance knowledge
Familiarity with MITRE ATT&CK Framework
...or spring semesters, students must be enrolled in three units or more at CMC (not on a waiting list.) Students may work during the summer break without being enrolled in summer classes if they meet the eligibility requirements for the following fall semester; if not, they...
...Job Description Job Description Medicaid Business / QA Analyst ~712+ Month Contract | Remote | No ThirdParty Firms | Medicaid SME Required ~ Candidates with previous State Medicaid program experience will be given strong consideration. ~ Drug screen and background...
Transportation Safety Manager - Orange CountyEOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran...
...Underground Equipment Operator This position is an experienced... ...Safety, Sustainability, and Continuous Improvement Ensure the company... ...and repair duties on mine equipment and other manual related... ...following underground mining machines; Scoop, Shuttle Car, Roof Bolter...
Job Description Job Description Flexible hours experience preferred in pet grooming industry ,will commission based and very lucrative part time to full time depending on your availability