Skip to content

Open role

Senior Penetration Tester (Web and API), Contract

Lead fixed-scope web application and API penetration tests for US companies, from scoping call to retest. Manual-first testing against OWASP WSTG, ASVS and the API Security Top 10, with findings that hold up in front of a SOC 2 or PCI DSS auditor.

Engagement
Contract, paid per engagement
Location
Remote, United States
Pay range
$175,000 to $265,000 per year
Posted
September 14, 2026

The engagement

Contract, remote within the United States, paid per engagement. A typical engagement is five to ten testing days plus a retest, scheduled around your availability. Onboarding to the Invadel platform and reporting templates takes a day.

What you will do

  • Run manual web application and API tests across every user role: authorization, authentication and session handling, injection, business logic, SSRF, file handling and deserialization.
  • Confirm or discard every automated result by hand, chain findings the way an attacker would, and prove impact safely within the rules of engagement.
  • Escalate critical findings the day they are confirmed.
  • Write the report: executive summary, technical findings with reproduction steps and CVSS scores, remediation in priority order, and the framework mapping the client needs.
  • Perform the retest of remediated findings and update the report.
  • Join the scoping call when the client wants the tester in the room.

What we need

  • Five or more years of hands-on application penetration testing, with web and API work as the majority of it.
  • Depth on at least one modern stack (single-page applications, GraphQL, OAuth and OIDC flows, multi-tenant SaaS).
  • Based in the United States with authorization to work here; engagements run on US time and clients are US companies.
  • Reports written for two readers at once: an engineer who has to fix the finding and an auditor who has to accept the evidence. A redacted sample report is part of the application.
  • Comfortable working to a fixed, written scope and saying early when something in it is wrong.
  • Two professional references from people who have seen your work on a live engagement.

Nice to have

  • Mobile application testing (MASVS and MASTG) or cloud testing on AWS, Azure or GCP, so one tester can cover a combined scope.
  • Published research, tooling or disclosed vulnerabilities in third-party software.
  • An offensive security certification is welcome; it does not replace a verifiable engagement record.