Web Application Penetration Tester – Technical Lead (In Office or Remote)

Freddie Mac logoFreddie Mac
McLean, VA, US
Remote
$150K–$224K/yr
Posted
1 weeks ago
Location
McLean, VA, US
Job Type
fulltime
Apply Now Remote Position
Posted 1 weeks ago

Job Description

Lead web application penetration testing and Red Team assessments to strengthen Freddie Mac's information security defenses.
Join Freddie Mac's Red Team as an Information Security Tech Lead to strengthen organizational defenses by simulating attacker objectives. This role focuses on advanced penetration testing across web applications, infrastructure, networks, cloud, and social engineering. **Key Responsibilities:** * Lead web application penetration assessments, providing tailored remediations and translating complex security concepts. * Proactively identify vulnerabilities in web applications, APIs, and cloud environments. * Integrate web application security into broader threat emulation scenarios. * Develop and maintain scripts, tools, and methodologies to enhance team capabilities. * Mentor junior team members and contribute to security policy improvement. **Required Qualifications:** * 8-10 years of experience in web application penetration testing. * One or more technical certifications: OSWA, OSWE, Burp Suite Certified Practitioner, eWPT, eWPTX. * Expertise in identifying, exploiting, and remediating web vulnerabilities (SQLi, XSS, SSRF, CSRF). * Solid understanding of web technologies (HTTP, DNS, HTML, JS, REST, GraphQL, Java, .NET, SQL/noSQL, OAuth) and infrastructure (cloud native, containers, PaaS). * In-depth knowledge of secure development practices (DevSecOps, secure code review) and security frameworks (OWASP, CWE, MITRE). * Proficient with common web application penetration testing tools (Burp Suite, Project Discovery, sqlmap) and familiar with WAF bypasses. * Ability to work East Coast hours. **Preferred Skills:** * Web-related public research (advisories, disclosures) or Bug Bounty experience. * Proficiency in at least one scripting/programming language (Python, JavaScript, C#, Java).

About Freddie Mac

Freddie Mac logo

The Federal Home Loan Mortgage Corporation (FHLMC), commonly known as Freddie Mac, is an American publicly traded, government-sponsored enterprise (GSE), headquartered in Tysons, Virginia. The FHLMC was created in 1970 to expand the secondary market for mortgages in the US. Along with its sister organization, the Federal National Mortgage Association, Freddie Mac buys mortgages, pools them, and sells them as a mortgage-backed security (MBS) to private investors on the open market. This secondary mortgage market increases the supply of money available for mortgage lending and increases the money available for new home purchases. The name "Freddie Mac" is a variant of the FHLMC initialism of the company's full name that was adopted officially for ease of identification.

Industry
Other
Company Size
Founded
1970

Similar Jobs

Development Senior Director – Corporate Delivery

Freddie Mac

McLean, VA
$216K–$324K/yr

Lead technology teams to deliver innovative solutions for corporate divisions.

Web Development Engineer, Knowledge Management & Governance, Worldwide Field Enablement

Amazon Web Services

Arlington, VA, US
$72K–$173K/yr

Develop and optimize web-based content architectures, enhancing sales enablement content discoverability and management processes.

Full Stack Web & App Developer

Colorectal Cancer Alliance

Washington, DC, US
$120K–$140K/yr

⚠️ Summary missing