Red Team Engineer
Job in
Blue Springs, Jackson County, Missouri, 64014, USA
Listed on 2026-08-02
Listing for:
Jobtailor
Full Time
position Listed on 2026-08-02
Job specializations:
-
Software Development
Job Description & How to Apply Below
Responsibilities
- Conduct deep manual penetration tests against web applications, REST/GraphQL APIs, and microservices — focusing on authentication, authorization (IDOR/BOLA), session management, injection, and business logic flaws.
- Perform source-code-assisted testing (grey-box/white-box) using access to application repositories to identify vulnerabilities that black-box testing misses.
- Test multi-tenant isolation boundaries — proving or disproving cross-tenant data access, privilege escalation, and tenant-escape scenarios in SaaS platforms.
- Assess authentication and session architectures: OAuth/OIDC flows, JWT handling, MFA bypass, token lifecycle, and session revocation effectiveness.
- Validate authorization models end-to-end — from API gateway to data layer — identifying gaps where opt-in security filters can be bypassed or omitted.
- Execute targeted assessments of high-risk application changes, new features, and integrations as part of the secure development lifecycle.
- Use AI tools (LLMs, copilots, agentic frameworks) to accelerate vulnerability discovery, payload generation, reconnaissance, and report writing.
- Build and maintain AI-assisted attack workflows — automated recon pipelines, intelligent fuzzing, pattern-based code review, and exploit chain analysis.
- Assess AI-integrated application features for prompt injection, training data leakage, model manipulation, excessive agency, and insecure output handling (OWASP LLM Top 10).
- Conduct penetration tests against cloud-hosted applications and services in AWS and Azure — including serverless functions, container workloads, and managed services.
- Test cloud identity and access configurations — IAM policies, role assumptions, cross-account access, service principal permissions, and privilege escalation paths.
- 4+ years of hands‑on experience in penetration testing, with a primary focus on web applications and APIs.
- Deep understanding of web application vulnerabilities beyond OWASP Top 10 — including business logic flaws, authorization model weaknesses (IDOR/BOLA), race conditions, and authentication/session architecture attacks.
- Experience testing multi-tenant SaaS applications and understanding tenant isolation patterns and failure modes.
- Proficiency with web application testing tools:
Burp Suite Professional, custom extensions, and manual testing methodologies. - Scripting and automation skills (Python, JavaScript, or similar) for exploit development, custom tooling, and test automation.
- Working knowledge of cloud platforms (AWS and/or Azure) — enough to test cloud-hosted applications and understand IAM, networking, and service configurations.
- Familiarity with source code review for security — ability to read and analyze application code (.NET/C#, Java, JavaScript/Type Script, or Python) to identify vulnerabilities.
- Experience producing professional penetration‑test reports with clear evidence, risk ratings, and remediation guidance.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×