Open role
Senior Penetration Tester (Web and API), Contract
Lead fixed-scope web application and API penetration tests for US companies, from scoping call to retest. Manual-first testing against OWASP WSTG, ASVS and the API Security Top 10, with findings that hold up in front of a SOC 2 or PCI DSS auditor.
- Engagement
- Contract, paid per engagement
- Location
- Remote, United States
- Pay range
- $175,000 to $265,000 per year
- Posted
- September 14, 2026
The engagement
Contract, remote within the United States, paid per engagement. A typical engagement is five to ten testing days plus a retest, scheduled around your availability. Onboarding to the Invadel platform and reporting templates takes a day.
What you will do
- Run manual web application and API tests across every user role: authorization, authentication and session handling, injection, business logic, SSRF, file handling and deserialization.
- Confirm or discard every automated result by hand, chain findings the way an attacker would, and prove impact safely within the rules of engagement.
- Escalate critical findings the day they are confirmed.
- Write the report: executive summary, technical findings with reproduction steps and CVSS scores, remediation in priority order, and the framework mapping the client needs.
- Perform the retest of remediated findings and update the report.
- Join the scoping call when the client wants the tester in the room.
What we need
- Five or more years of hands-on application penetration testing, with web and API work as the majority of it.
- Depth on at least one modern stack (single-page applications, GraphQL, OAuth and OIDC flows, multi-tenant SaaS).
- Based in the United States with authorization to work here; engagements run on US time and clients are US companies.
- Reports written for two readers at once: an engineer who has to fix the finding and an auditor who has to accept the evidence. A redacted sample report is part of the application.
- Comfortable working to a fixed, written scope and saying early when something in it is wrong.
- Two professional references from people who have seen your work on a live engagement.
Nice to have
- Mobile application testing (MASVS and MASTG) or cloud testing on AWS, Azure or GCP, so one tester can cover a combined scope.
- Published research, tooling or disclosed vulnerabilities in third-party software.
- An offensive security certification is welcome; it does not replace a verifiable engagement record.