The Penetration Testing Engineer – Application Security is a mid-level role for a tester who has grown beyond the basics and can independently execute penetration tests within a primary domain of expertise. Engineers are offensive security subject matter experts – conducting full assessments with minimal supervision, contributing to methodology improvements, and acting as a point of contact for clients during engagements. By this stage, they are capable of scoping and planning a test in their domain, executing tests, and producing and communicating detailed reports with practical remediation advice.
Mid-level testers act as the technical client focal within engagements, leading technical execution for assigned projects.
Requirements
Typical Experience: ~3–5 years of penetration testing experience, during which they have performed numerous assessments. At this point, they have a track record of completed pen tests and proven competencies.
Domain Expertise: Mastery in at least one penetration testing domain. For example, an engineer might be an expert in Web Application Security – adept with advanced web vulnerabilities (beyond OWASP Top 10, including logic flaws, deserialization, etc.), skilled in using Burp Suite for complex testing, and possibly familiar with secure code review.
Technical Skills: Strong practical skills and tool usage. Mid-level testers are comfortable with a variety of pen testing tools and techniques. This includes network scanners (Nmap, Nessus), exploitation frameworks (Metasploit, Cobalt Strike), web testing suites (Burp Suite, OWASP ZAP), and scripting/programming to automate tasks or develop custom exploits (common languages include Python, PowerShell, or Bash). Understanding manual testing techniques – for example, crafting customized payloads, bypassing filters, or chaining vulnerabilities. An engineer at this level is often responsible for ensuring the accuracy of findings (minimal false positives) and may contribute new findings to the team’s knowledge base.
Soft Skills: Solid communication and consulting skills. By now, the engineer can write thorough technical reports that require only light review, translating technical findings into clear, actionable recommendations. They are also responsive and growing in client-facing abilities, able to lead client briefing calls, deliver vulnerability walkthroughs, and handle questions from stakeholders. Their time management and project coordination skills have improved, enabling them to handle multiple projects or deadlines.
Certifications (Optional): Many mid-levels pen testers obtain well-regarded certifications as a by-product of developing their skills. Examples include OSCP, GWAPT (Web Application Testing), GPEN (Network Penetration), OSWE (Web Exploit Developer), etc. These certifications reinforce their domain expertise, but hands-on experience and successful engagements remain the primary proof of competency.
Expertise that aligns to our approach:
Benefits
About Evolve Security
Evolve Security is a next generation cybersecurity services firm headquartered in Chicago, IL powered by the Darwin Attack® Platform. We are dedicated to improving our client’s security posture by providing Attack Surface Management (ASM), Vulnerability Management as a Service (VMaaS), Continuous Penetration Testing (CPT) and cyber advisory.
In addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, “Evolve Academy”, currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies.
We are passionate about directly improving our customers’ security posture, and we proudly train others to help meet the need for qualified cybersecurity talent.
Why Join Evolve Security?
Job Description The Lead Cook is responsible for cooking and preparing food using standard recipes and production guidelines while following food safety, food handling, and sanitation procedures. The individual in this role should safely handle knives and equipment ...
...environment where staff and faculty are key contributors to UCs success. Job Overview The Department of Civil and Architectural Engineering and Construction Management (CAECM) in the College of Engineering and Applied Science (CEAS) at the University of Cincinnati...
...Gold Medal International (GMI) has established itself as one of the leading hosiery and accessories companies in the industry. GMI designs, sources, and manufactures wholesale socks and accessories for a customer base ranging from small independent stores to the most prestigious...
...As a Human Resources Specialist, youll play a crucial role in assisting your fellow Soldier's progress in their Army careers, providing promotion and future training information. Youll ensure the necessary support is also provided to commanders across all branches....
...GENERAL SUMMARY : The Service Ambassador Loss Prevention, is responsible for providing excellent customer service, protecting company assets through activities in safety, inventory recovery, and internal and external theft deterrence. The main objective of the Service...