user avatar

Test Engineer III

Seneca Holdings

Posted today

Job Requirements

Remote
Public Trust Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Position Title: Test Engineer III - Penetration Tester
Location: Remote
Clearance Requirements: Public Trust Clearance
Position Status: Full-Time Contract

Position Description:
Seneca Resources is seeking an experienced Test Engineer III - Penetration Tester to support advanced cybersecurity testing and offensive security initiatives within a large-scale enterprise environment. This role is ideal for a highly skilled security professional with strong experience in web application, API, network, red team, and purple team penetration testing. The successful candidate will identify vulnerabilities, validate attack paths, assess security controls, and work closely with security engineering and Cyber Security Operations Center (CSOC) teams to improve overall enterprise security. This position offers the opportunity to work with modern offensive security tools, emerging AI-powered security technologies, and established cybersecurity frameworks.

Key Responsibilities:
  • Perform web application, API, network, and infrastructure penetration testing to identify vulnerabilities and exploitable attack paths.
  • Conduct penetration tests using Burp Suite Professional, DAST tools, Kali Linux, Metasploit Pro, Cobalt Strike, and other industry-standard offensive security tools.
  • Plan and execute Red Team engagements, including reconnaissance, exploitation, privilege escalation, lateral movement, and post-exploitation activities.
  • Conduct authorized phishing and social engineering simulations to evaluate user susceptibility and validate enterprise security controls.
  • Perform Purple Team exercises in collaboration with security engineering and CSOC teams to validate detection, monitoring, alerting, and response capabilities.
  • Apply AI and AI-enabled penetration testing techniques to evaluate emerging attack methods and security risks.
  • Develop scripts and automation using Python and/or PowerShell to support security testing, reconnaissance, vulnerability validation, and reporting.
  • Conduct penetration testing activities supporting PCI-DSS compliance and other applicable security requirements.
  • Analyze vulnerabilities and attack paths and communicate technical findings, business risks, and remediation recommendations to technical and non-technical stakeholders.
  • Document test plans, methodologies, findings, evidence, attack paths, and remediation recommendations through clear technical reports.
  • Apply OWASP Application Security Verification Standard (ASVS) and MITRE ATT&CK frameworks to penetration testing and adversary simulation activities.

Required Skills/Education:
  • 8+ years of relevant cybersecurity, penetration testing, offensive security, or related experience.
  • Bachelor's degree from an accredited college or university in cybersecurity, information technology, computer science, information systems, or a related field.
  • If the degree is not in an applicable field, 4 additional years of related experience may be substituted.
  • Strong hands-on experience with web application, API, and network penetration testing.
  • Experience using Burp Suite Professional or comparable Dynamic Application Security Testing (DAST) tools.
  • Advanced knowledge of Kali Linux and commonly used penetration testing tools.
  • Experience with Metasploit Pro and Cobalt Strike in authorized red team or adversary simulation engagements.
  • Demonstrated experience planning and executing Red Team and Purple Team engagements.
  • Experience evaluating security monitoring and detection capabilities in collaboration with CSOC/SOC and security engineering teams.
  • Strong scripting and automation skills using Python and/or PowerShell.
  • Knowledge of OWASP ASVS and the MITRE ATT&CK framework.
  • Experience conducting penetration testing in environments subject to PCI-DSS requirements.
  • Strong technical writing and communication skills, including the ability to clearly explain vulnerabilities, exploitation techniques, attack paths, and remediation strategies.
  • Experience with AI security, AI-assisted penetration testing, or penetration testing of AI-enabled applications is highly desirable.
  • A penetration testing or offensive security certification is preferred, such as:
    • Offensive Security Certified Professional (OSCP)
    • GIAC Certified Penetration Tester (GPEN)
    • GIAC Web Application Penetration Tester (GWAPT)
    • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
    • Other recognized offensive security or penetration testing certifications


About Seneca Resources
At Seneca Resources, we are more than just a staffing and consulting firm, we are a trusted career partner. With offices across the U.S. and clients ranging from Fortune 500 companies to government organizations, we provide opportunities that help professionals grow their careers while making an impact. When you work with Seneca, you're choosing a company that invests in your success, celebrates your achievements, and connects you to meaningful work with leading organizations nationwide. We take the time to understand your goals and match you with roles that align with your skills and career path. Our consultants and contractors enjoy competitive pay, comprehensive health, dental, and vision coverage, 401(k) retirement plans, and the support of a dedicated team who will advocate for you every step of the way. Seneca Resources is proud to be an Equal Opportunity Employer, committed to fostering a diverse and inclusive workplace where all qualified individuals are encouraged to apply.
group id: 10530356

Similar Jobs


Job Category
IT - QA and Test
Clearance Level
Public Trust