Brooklyn Park , MN
|Remote
|Contract
Brooklyn Park, MN
|Remote
|Contract
Join a dynamic security engineering opportunity focused on protecting modern web applications and APIs in an enterprise environment. This role offers the chance to lead end-to-end penetration testing efforts, partner with engineering teams, and help strengthen security through clear findings and practical remediation guidance.
Responsibilities
- Plan and execute penetration tests from scoping through exploitation, validation, and reporting.
- Assess web applications and APIs for common and advanced security vulnerabilities, including authentication, authorization, and injection issues.
- Use industry-standard testing tools such as Burp Suite and Nmap to identify and verify risks.
- Create clear, actionable documentation that helps engineering teams understand and remediate findings.
- Collaborate with technical teams to validate fixes and support remediation efforts.
- Develop scripts or lightweight automation in Python or Go to improve testing workflows.
- Contribute to security efforts across additional areas such as mobile, hardware/embedded systems, or third-party platforms when applicable.
- Support risk identification efforts through threat modeling and pre-deployment review activities.
Skills
- 5+ years of hands-on penetration testing experience, with a strong focus on web applications and APIs.
- Proven ability to perform full penetration tests independently and communicate results effectively.
- Deep understanding of web application security principles and common vulnerability classes, including OWASP Top 10.
- Advanced experience using Burp Suite, along with familiarity with Nmap and related exploitation tools.
- Ability to write scripts or automation in Python or Go to support technical work.
- Strong documentation skills with the ability to translate technical findings into clear remediation guidance.
- Experience working with engineering teams in a collaborative, solution-oriented way.
- Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience, plus 7+ years in cybersecurity with increasing responsibility in penetration testing.
Preferred Skills
- Experience testing mobile applications, hardware or embedded systems, or vendor/third-party platforms.
- Familiarity with PCI-related penetration testing requirements and compliance environments.
- Exposure to bug bounty programs, including triage, validation, and escalation.
- Experience mentoring other testers or providing technical guidance to peers.
- Strong understanding of networking and system architecture in large-scale environments.
- Interest in improving penetration testing processes, tooling, and automation.
- Relevant certifications such as OSCP, OSCE, OSWE, or CISSP.
Horizontal is committed to building an inclusive workplace where diverse perspectives are valued and everyone has the opportunity to contribute and succeed. We welcome candidates from all backgrounds and are dedicated to fostering a culture of equity, respect, and belonging.
By applying for this position, you acknowledge and agree that Horizontal Talent may contact you regarding your application using automated technology, including phone calls, SMS/text messages, or email, which may be delivered by our virtual AI recruiter, Alex.
Horizontal is committed to taking affirmative action to employ and advance in employment qualified individuals with disabilities and protected veterans. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process or participate in the interview process, click here to request accommodation assistance.
All applicants applying must be legally authorized to work in the country of employment.