Point your AI agent at freehire and let it find you a job.

Get the CLI →

Security Engineer II

Discussion

About the Role
We are looking for a Senior Penetration Tester who combines strong offensive testing skills with deep application security and secure code review expertise. This role is for someone who doesn't just test applications from the outside — you can read and reason about source code like a developer, trace vulnerable logic from input to sink, and then convert those code-level findings into real, working security test cases and exploits that prove impact end-to-end. You'll own full-cycle assessments: black-box testing, white-box/source-assisted review, and validation — tying it all together into a coherent risk narrative for engineering and leadership, with an attacker's mindset applied throughout. Exposure to broader red team operations is a plus and will allow you to extend application-layer footholds into wider adversary simulation scenarios.
Key Responsibilities
Application Penetration Testing (Black-box & White-box)

Plan, scope, and execute end-to-end penetration tests on web applications, APIs, and mobile apps using both black-box and source-assisted (white-box) methodologies.

Perform full attack-surface mapping, auth flows, session management, API contracts, business logic, access control boundaries - before diving into exploitation.

Chain vulnerabilities together to demonstrate real business impact (e.g., IDOR + broken auth → account takeover; SSRF → internal pivot → sensitive data exposure).

Validate and retest fixes; ensure remediations actually close the exploited path, not just the symptom.

Manual Secure Code Review

Conduct manual, in-depth secure code reviews across languages such as Java, Python, JavaScript/TypeScript (Node.js), Go, C#, and PHP — going beyond automated scanner output.

Trace data flow from source (user input, external API, file upload, etc.) to sink (DB query, deserialization, template engine, OS command, file system, etc.) to confirm real exploitability and eliminate false positives.

Identify vulnerability classes including injection attacks (SQL, NoSQL, Command, LDAP, XXE), insecure deserialization, authentication and session flaws, IDOR and broken access control, SSRF, race conditions, cryptographic misuse, and business logic flaws.

Turning Code Findings into Working Security Tests

For every significant code-review finding, build a corresponding proof-of-concept, exploit script, or test case that demonstrates exploitability in a running environment — not just a theoretical writeup.

Develop custom scripts/tools (Python, Go, Bash) to weaponize and automate exploitation of identified code patterns across the codebase (e.g., identifying a vulnerable pattern, then scripting mass validation across multiple endpoints/services).

Translate secure code review findings into repeatable regression security tests that can be reused across engagements and retesting cycles to catch reintroduction of the same bug class.

Bridge the gap between "this line of code looks dangerous" and "here's the request/script/payload that proves it," making findings actionable and unambiguous for developers.

Offensive Tooling & Automation

Go beyond automated scan output — treat static/dynamic analysis as a recon and target-prioritization step, then manually validate and weaponize findings into working exploits, the way an attacker would triage a leaked or decompiled codebase.

Build and maintain a personal/team exploit and payload library mapped to recurring vulnerability patterns — reusable proof-of-concepts, request templates, and scripts that turn a static finding into a live, demonstrable attack within minutes, speeding up engagement turnaround.

Chain application-layer findings into deeper exploitation paths — e.g., using a discovered IDOR or auth flaw to escalate privileges within the app, or an SSRF/file-read bug to pivot into other exposed application components or internal services reachable from the app.

Continuously stress-test your own exploit library and detection logic against the live application — attempt to bypass existing input validation, WAF rules, and app-layer guardrails to ensure findings reflect genuine adversary capability, not just tool coverage.

Extending Findings into Red Team Scenarios (Good to Have)

Use application-layer footholds (e.g., an SSRF, exposed internal endpoint, or leaked credential from source code) as an entry point into broader adversary simulation — pivoting from app compromise toward internal network or Active Directory attack paths where in scope.

Apply working knowledge of C2 concepts (beaconing, traffic patterns, evasion) to understand how an application-layer compromise could realistically be leveraged for persistence or lateral movement in a full red team engagement.

Bring an adversary-emulation mindset to engagements — thinking beyond "is this exploitable" to "how would a real threat actor chain this into a larger compromise."

Reporting & Communication

Author clear, detailed technical reports that connect the dots: vulnerable code snippet → proof-of-concept/exploit → business impact → remediation guidance.

Map findings to OWASP Top 10, SANS Top 25, and CWE, with risk ratings and clear reproduction steps.

Present findings to both engineering teams (code-level detail) and leadership (business risk, executive summary).

Support developers during remediation — reviewing patches and confirming the fix addresses root cause, not just the trigger.

Mentorship & Program Development

Mentor junior pentesters/AppSec engineers on manual code review techniques and exploit development.

Help mature the internal AppSec/pentest methodology — playbooks, custom tooling, and code-review checklists tailored to the tech stacks in use.

Stay current with new vulnerability classes, framework-specific CVEs, and emerging exploitation techniques; incorporate them into review checklists and test cases.

Required Qualifications

5+ years in penetration testing / offensive security, with strong demonstrable experience in application security testing and manual secure code review (not just automated scanning).

Proven ability to read and understand source code fluently in at least one major backend language (Java, Python, C#, Go, or JavaScript/TypeScript), enough to trace logic, understand data flow, and spot subtle flaws.

Track record of converting static findings (from code review) into working dynamic proof-of-concepts — able to go from "vulnerable line of code" to an actual exploit/request/script that proves it.

Strong scripting/programming skills (Python, Go, Bash, or similar) for building custom test scripts, automation, and exploit tooling.

Solid understanding of web/API architecture and common vulnerability classes (OWASP Top 10, SANS Top 25, CWE).

Hands-on experience with web/API application testing toolchains (e.g., Burp Suite Pro, Postman) and static/dynamic code analysis approaches.

Strong report writing and communication skills, able to explain code-level vulnerabilities to both developers and non-technical stakeholders.

Preferred Qualifications

Certifications such as OSWE, OSCP, GWAPT, CRTE, or equivalent — OSWE especially valued given the code-review/exploit-dev focus.

Prior red team experience — comfort with Active Directory attack paths, lateral movement, privilege escalation, and C2 frameworks (e.g., Cobalt Strike, Sliver, Metasploit) is a strong plus.

Experience with mobile application security testing (iOS/Android) including static analysis of app binaries/source.

Knowledge of compliance frameworks (PCI-DSS, ISO 27001, SOC 2) as they relate to application security testing.

Active participation in bug bounty programs with a strong track record of validated findings is a plus.

Speaking engagements at security/bug bounty conferences (e.g., DEF CON, Black Hat, Nullcon, c0c0n, BSides) or publishing security research/write-ups is a strong plus.

Company Benefits & Perks:

Competitive salary package.
Performance based annual bonus (cash and stocks).
Hybrid working model (3 days office/week).
Group Medical & Life Insurance.
Modern offices with free amenities & fully stocked cafeterias.
Monthly food card & company paid snacks.
Hardship/shift allowance with company provided pickup & drop facility*
Attractive employee referral bonus.
Frequent company sponsored team building events and outings.

  • Depending upon the shifts.

**The benefits package is subject to change at the management's discretion.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available