MNC InsiderMNC Insider

Senior Application Penetration Tester

Chubb

Senior Application Penetration Tester

full-timePosted: Aug 24, 2026Updated: Aug 29, 2026Philadelphia, PA, United States

Job Description

Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native/containerized, and AI/LLM-integrated applicationsAssess AI/ML and generative AI-powered features for risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure, aligned to the OWASP Top 10 for LLM Applications and MITRE ATLASPartner with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelinesEvaluate cloud-native and containerized workloads (AWS, Azure, GCP, Docker, Kubernetes) and Infrastructure as Code for misconfigurations and weak security controlsTest modern API architectures (REST, GraphQL, gRPC), including OAuth2, OIDC, and JWT authentication and authorization flaws, and microservices-based applicationsConduct mobile application security testing and reverse engineering, including hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypassOwn the overall vulnerability remediation status of the global application portfolio, and serve as the primary point of contact for application teams on remediation mattersManage application risk rating processes and ensure timely risk scoring of new and changing applicationsBuild and maintain dashboards and status reports for portfolio leads and CIOs, and follow up on overdue vulnerabilities to meet compliance timelinesDevelop clear, actionable penetration test reports and communicate findings and remediation strategy to both technical and executive stakeholdersResearch emerging attack techniques and tooling, and drive automation and process improvements across the testing program Minimum:Prior experience managing Information Security projectsBachelor's Degree in Computer Science, Engineering, or other Engineering or Technical discipline, or equivalent relevant experienceMinimum of 2 years' professional experience performing web application, API endpoint, and mobile (iOS & Android) penetration testingKnowledge of prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assetsKnowledge of industry standards regarding vulnerability management, including Common Vulnerabilities and Exposures (CVE) and Common Vulnerability Scoring System (CVSS)Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening and security baselines, and web server and database securityKnowledge of penetration testing principles, tools, and techniquesWorking experience with industry frameworks (OWASP, OWASP API Security Top 10, OWASP Top 10 for Large Language Model (LLM) Applications, NIST, NIST AI Risk Management Framework, MITRE ATT&CK, etc.)Comfortable working outside their comfort zone with a willingness to learnExcellent verbal and written communication skillsStrong analytical skillsStrong team player with the ability to work independentlyStrong project management skills and ability to multi-taskSelf-motivated with strong initiativeKnowledge of computer networking concepts and protocols, and application security methodologiesSkill in performing impact/risk assessmentsFamiliarity with modern application architectures, including cloud-native (AWS, Azure, GCP), containerized (Docker, Kubernetes), microservices, and API-first (REST, GraphQL, gRPC) designsFoundational understanding of AI/ML and generative AI security risks (e.g., prompt injection, model manipulation, sensitive data leakage) is a plus Nice To Have:Strong understanding of secure SDLC, exploit/attack techniques, and core networking, application, and OS concepts, with the ability to manipulate application logic, bypass security controls, and develop exploitsExperience scoping and leading engagements end-to-end — from kickoff through remediation tracking — and improving testing efficiency through automation, tooling, and process improvementsProficient with industry-standard tools across categories: Kali Linux, Metasploit, Nmap, Burp Suite/OWASP ZAP (web); Santoku, Genymotion, APKTool, JD-GUI (mobile); SQLMap, Semgrep, Snyk, Checkmarx/AppScan/Veracode (code); Postman/Insomnia (API); Trivy/Grype, Prowler/ScoutSuite (cloud & containers); and Garak/PyRIT (AI red-teaming)Skilled in identifying OWASP Top 10 (Web & Mobile), OWASP API Security Top 10, and OWASP LLM Top 10 vulnerabilities, and developing secure coding checklists based on OWASP ASVSExperience conducting full-scope assessments and penetration tests — web, mobile, API, social engineering, and server/client-side attacks — including mobile reverse engineering (hardcoded credentials, SQLi, keychain exposure, anti-emulator/obfuscation bypass)Experience assessing cloud-native and containerized applications (AWS, Azure, GCP, Docker, Kubernetes), modern CI/CD pipelines and Infrastructure as Code, and modern API architectures (REST, GraphQL, gRPC) including OAuth2/OIDC/JWT flawsExperience or working knowledge testing AI/ML and generative AI features for risks such as prompt injection, insecure output handling, training data poisoning, and sensitive data disclosure, aligned to the OWASP LLM Top 10 and MITRE ATLAS, plus working knowledge of securing AI agent/orchestration frameworks (LangChain, Semantic Kernel, AutoGen) and RAG vector databasesSkilled in code analysis, exploit development, and using attacker tools/tactics/procedures to identify, validate, and demonstrate vulnerabilities an adversary could exploitAbility to analyze findings (including root cause analysis), risk-rate vulnerabilities by actual business impact, and prioritize key risk areasAbility to document findings clearly, including reproduction steps, and produce comprehensive, accurate penetration test reportsAbility to research and recommend practical short- and long-term remediations, and communicate findings and strategy effectively to both technical and executive stakeholdersExperience working closely with development teams to track remediation through to production deployment, maintain vulnerability status dashboards, and follow up on overdue items to meet compliance timelinesPreferred certifications: OSCP, OSWE, GWAPT, GPEN, CEH, GCPN, CCSP, or equivalent AI/ML security credentialsStrong communicator and collaborative team player, able to adapt and reprioritize as project needs shift

Locations

  • Philadelphia, PA, United States
  • Philadelphia - 2000 Arch St

Skills Required

  • industry standards regarding vulnerability managementintermediate
  • technologyintermediate
  • penetration testing principlesintermediate
  • industry frameworksintermediate
  • computer networking conceptsintermediate
  • modern application architecturesintermediate
  • industry-standard tools across categories: Kali Linuxintermediate
  • identifying OWASP Top 10intermediate
  • securing AI agent/orchestration frameworksintermediate
  • code analysisintermediate

Required Qualifications

  • Prior experience managing Information Security projects (experience)
  • Bachelor's Degree in Computer Science, Engineering, or other Engineering or Technical discipline, or equivalent relevant experience (experience)
  • Minimum of 2 years' professional experience performing web application, API endpoint, and mobile (iOS & Android) penetration testing (experience, 2 years)
  • Knowledge of prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets (experience)
  • Knowledge of industry standards regarding vulnerability management, including Common Vulnerabilities and Exposures (CVE) and Common Vulnerability Scoring System (CVSS) (experience)
  • Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening and security baselines, and web server and database security (experience)
  • Knowledge of penetration testing principles, tools, and techniques (experience)
  • Working experience with industry frameworks (OWASP, OWASP API Security Top 10, OWASP Top 10 for Large Language Model (LLM) Applications, NIST, NIST AI Risk Management Framework, MITRE ATT&CK, etc.) (experience)
  • Comfortable working outside their comfort zone with a willingness to learn (experience)
  • Excellent verbal and written communication skills (experience)
  • Strong analytical skills (experience)
  • Strong team player with the ability to work independently (experience)
  • Strong project management skills and ability to multi-task (experience)
  • Self-motivated with strong initiative (experience)
  • Knowledge of computer networking concepts and protocols, and application security methodologies (experience)
  • Skill in performing impact/risk assessments (experience)
  • Familiarity with modern application architectures, including cloud-native (AWS, Azure, GCP), containerized (Docker, Kubernetes), microservices, and API-first (REST, GraphQL, gRPC) designs (experience)
  • Foundational understanding of AI/ML and generative AI security risks (e.g., prompt injection, model manipulation, sensitive data leakage) is a plus (experience)
  • Strong understanding of secure SDLC, exploit/attack techniques, and core networking, application, and OS concepts, with the ability to manipulate application logic, bypass security controls, and develop exploits (experience)
  • Experience scoping and leading engagements end-to-end — from kickoff through remediation tracking — and improving testing efficiency through automation, tooling, and process improvements (experience)
  • Proficient with industry-standard tools across categories: Kali Linux, Metasploit, Nmap, Burp Suite/OWASP ZAP (web); Santoku, Genymotion, APKTool, JD-GUI (mobile); SQLMap, Semgrep, Snyk, Checkmarx/AppScan/Veracode (code); Postman/Insomnia (API); Trivy/Grype, Prowler/ScoutSuite (cloud & containers); and Garak/PyRIT (AI red-teaming) (experience)
  • Skilled in identifying OWASP Top 10 (Web & Mobile), OWASP API Security Top 10, and OWASP LLM Top 10 vulnerabilities, and developing secure coding checklists based on OWASP ASVS (experience)
  • Experience conducting full-scope assessments and penetration tests — web, mobile, API, social engineering, and server/client-side attacks — including mobile reverse engineering (hardcoded credentials, SQLi, keychain exposure, anti-emulator/obfuscation bypass) (experience)
  • Experience assessing cloud-native and containerized applications (AWS, Azure, GCP, Docker, Kubernetes), modern CI/CD pipelines and Infrastructure as Code, and modern API architectures (REST, GraphQL, gRPC) including OAuth2/OIDC/JWT flaws (experience)
  • Experience or working knowledge testing AI/ML and generative AI features for risks such as prompt injection, insecure output handling, training data poisoning, and sensitive data disclosure, aligned to the OWASP LLM Top 10 and MITRE ATLAS, plus working knowledge of securing AI agent/orchestration frameworks (LangChain, Semantic Kernel, AutoGen) and RAG vector databases (experience)
  • Skilled in code analysis, exploit development, and using attacker tools/tactics/procedures to identify, validate, and demonstrate vulnerabilities an adversary could exploit (experience)
  • Ability to analyze findings (including root cause analysis), risk-rate vulnerabilities by actual business impact, and prioritize key risk areas (experience)
  • Ability to document findings clearly, including reproduction steps, and produce comprehensive, accurate penetration test reports (experience)
  • Ability to research and recommend practical short- and long-term remediations, and communicate findings and strategy effectively to both technical and executive stakeholders (experience)
  • Experience working closely with development teams to track remediation through to production deployment, maintain vulnerability status dashboards, and follow up on overdue items to meet compliance timelines (experience)
  • Preferred certifications: OSCP, OSWE, GWAPT, GPEN, CEH, GCPN, CCSP, or equivalent AI/ML security credentials (certification)
  • Strong communicator and collaborative team player, able to adapt and reprioritize as project needs shift (experience)

Target Your Resume for "Senior Application Penetration Tester" , Chubb

Get personalized recommendations to optimize your resume specifically for Senior Application Penetration Tester. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Senior Application Penetration Tester" , Chubb

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

EngineeringEngineering

Answer 10 quick questions to check your fit for Senior Application Penetration Tester @ Chubb.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.