Senior Application Penetration Tester

ChubbPhiladelphia, PA

About The Position

Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native/containerized, and AI/LLM-integrated applications. Assess AI/ML and generative AI-powered features for risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure, aligned to the OWASP Top 10 for LLM Applications and MITRE ATLAS. Partner with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelines. Evaluate cloud-native and containerized workloads (AWS, Azure, GCP, Docker, Kubernetes) and Infrastructure as Code for misconfigurations and weak security controls. Test modern API architectures (REST, GraphQL, gRPC), including OAuth2, OIDC, and JWT authentication and authorization flaws, and microservices-based applications. Conduct mobile application security testing and reverse engineering, including hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypass. Own the overall vulnerability remediation status of the global application portfolio, and serve as the primary point of contact for application teams on remediation matters. Manage application risk rating processes and ensure timely risk scoring of new and changing applications. Build and maintain dashboards and status reports for portfolio leads and CIOs, and follow up on overdue vulnerabilities to meet compliance timelines. Develop clear, actionable penetration test reports and communicate findings and remediation strategy to both technical and executive stakeholders. Research emerging attack techniques and tooling, and drive automation and process improvements across the testing program.

Requirements

  • Senior Application Penetration Tester experience
  • Experience planning and executing penetration tests across web, mobile (iOS & Android), API, cloud-native/containerized, and AI/LLM-integrated applications
  • Experience assessing AI/ML and generative AI-powered features for risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure, aligned to the OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Experience partnering with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelines
  • Experience evaluating cloud-native and containerized workloads (AWS, Azure, GCP, Docker, Kubernetes) and Infrastructure as Code for misconfigurations and weak security controls
  • Experience testing modern API architectures (REST, GraphQL, gRPC), including OAuth2, OIDC, and JWT authentication and authorization flaws, and microservices-based applications
  • Experience conducting mobile application security testing and reverse engineering, including hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypass
  • Experience owning the overall vulnerability remediation status of the global application portfolio, and serving as the primary point of contact for application teams on remediation matters
  • Experience managing application risk rating processes and ensuring timely risk scoring of new and changing applications
  • Experience building and maintaining dashboards and status reports for portfolio leads and CIOs, and following up on overdue vulnerabilities to meet compliance timelines
  • Experience developing clear, actionable penetration test reports and communicating findings and remediation strategy to both technical and executive stakeholders
  • Experience researching emerging attack techniques and tooling, and driving automation and process improvements across the testing program

Responsibilities

  • Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native/containerized, and AI/LLM-integrated applications
  • Assess AI/ML and generative AI-powered features for risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure, aligned to the OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Partner with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelines
  • Evaluate cloud-native and containerized workloads (AWS, Azure, GCP, Docker, Kubernetes) and Infrastructure as Code for misconfigurations and weak security controls
  • Test modern API architectures (REST, GraphQL, gRPC), including OAuth2, OIDC, and JWT authentication and authorization flaws, and microservices-based applications
  • Conduct mobile application security testing and reverse engineering, including hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypass
  • Own the overall vulnerability remediation status of the global application portfolio, and serve as the primary point of contact for application teams on remediation matters
  • Manage application risk rating processes and ensure timely risk scoring of new and changing applications
  • Build and maintain dashboards and status reports for portfolio leads and CIOs, and follow up on overdue vulnerabilities to meet compliance timelines
  • Develop clear, actionable penetration test reports and communicate findings and remediation strategy to both technical and executive stakeholders
  • Research emerging attack techniques and tooling, and drive automation and process improvements across the testing program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service