Freddie Mac logo

Web Application Penetration Tester – Technical Lead (In Office Or Remote)

McLean, VA, US
Salary
$150K–$224K/yr
Job Type
fulltime
Posted
8/5/2025

Job Description

Summary

Lead web application penetration testing and Red Team assessments to strengthen Freddie Mac's information security defenses.

Join Freddie Mac's Red Team as an Information Security Tech Lead to strengthen organizational defenses by simulating attacker objectives. This role focuses on advanced penetration testing across web applications, infrastructure, networks, cloud, and social engineering.

  • *Key Responsibilities:**
  • Lead web application penetration assessments, providing tailored remediations and translating complex security concepts.
  • Proactively identify vulnerabilities in web applications, APIs, and cloud environments.
  • Integrate web application security into broader threat emulation scenarios.
  • Develop and maintain scripts, tools, and methodologies to enhance team capabilities.
  • Mentor junior team members and contribute to security policy improvement.
  • *Required Qualifications:**
  • 8-10 years of experience in web application penetration testing.
  • One or more technical certifications: OSWA, OSWE, Burp Suite Certified Practitioner, eWPT, eWPTX.
  • Expertise in identifying, exploiting, and remediating web vulnerabilities (SQLi, XSS, SSRF, CSRF).
  • Solid understanding of web technologies (HTTP, DNS, HTML, JS, REST, GraphQL, Java, .NET, SQL/noSQL, OAuth) and infrastructure (cloud native, containers, PaaS).
  • In-depth knowledge of secure development practices (DevSecOps, secure code review) and security frameworks (OWASP, CWE, MITRE).
  • Proficient with common web application penetration testing tools (Burp Suite, Project Discovery, sqlmap) and familiar with WAF bypasses.
  • Ability to work East Coast hours.
  • *Preferred Skills:**
  • Web-related public research (advisories, disclosures) or Bug Bounty experience.
  • Proficiency in at least one scripting/programming language (Python, JavaScript, C#, Java).


Apply Now

Similar Jobs

Company Details

Company Size:7,799
Founded:1970
Headquarters:Tysons, Virginia, U.S.(McLean mailing address)

About

The Federal Home Loan Mortgage Corporation (FHLMC), commonly known as Freddie Mac, is an American publicly traded, government-sponsored enterprise (GSE), headquartered in Tysons, Virginia. The FHLMC was created in 1970 to expand the secondary market for mortgages in the US. Along with its sister organization, the Federal National Mortgage Association, Freddie Mac buys mortgages, pools them, and sells them as a mortgage-backed security (MBS) to private investors on the open market. This secondary mortgage market increases the supply of money available for mortgage lending and increases the money available for new home purchases. The name "Freddie Mac" is a variant of the FHLMC initialism of the company's full name that was adopted officially for ease of identification.

View Company Profile

Actions

Apply Now