Want to hear how I work? Hit play.Kablio AI applies for you. You just show up to the interviewKablio AI helps you secure roles in construction, clean energy, facilities management, engineering, architecture, sustainability, environment and other physical world sectors.
Get hired, get rewarded!
Land a job through Kablio and earn a 5% salary bonus.
Exclusive benefits
5%Bonus
Web App Pen Tester (San Diego or Irvine)
Costar Group
Provides commercial real estate data, analytics, and marketing services.
Secure web applications and underlying infrastructure as a Pen Tester.
19d ago
$114,200 - $203,500
Junior (1-3 years)
Full Time
San Diego, CA
Office Full-Time
Company Size
4,700 Employees
Service Specialisms
No specialisms available
Sector Specialisms
Commercial Real Estate
Residential
Apartments
Hospitality
Industrial
Retail
Office
Multifamily
Role
What you would be doing
penetration testing
sdlc security
security tools
secure coding
ci/cd automation
security expertise
Conduct penetration tests on web applications and underlying infrastructure for vulnerabilities using both manual and automated techniques
Work with the software and product teams to help ensure applications are designed and implemented securely during the SDLC
Consume a variety of application security tools (DAST, SAST, SCA, Credential Scanning, IAC scanning) to secure web applications during development and production run-time
Recommend code changes to eliminate vulnerabilities
Utilize sustainable methods to automate finding feedback to generate developer work items and trigger re-scan when associated work items are closed
Automate security testing at various stages within the CI/CD pipeline
Hack the Box Penetration Testing Specialist (CPTS) / AD Pentesting Expert (CAPE)
Hack the Box Bug Bounty Hunter (CBBH) / Web Exploitation Expert (CWEE)
What you bring
metasploit
dast
defense-in-depth
certifications
mobile pentesting
cloud-native
Dynamic application security testing (DAST) through Metasploit, Burp Suite, OWASP ZAP, Acunetix, etc.
Experience with mobile application penetration testing
Experience with defense-in-depth strategies to help mitigate existing risk within applications
Those certifications can be substituted with considerable experience in CTFs, impressive CVEs, or impressive bug bounty reports.
Ability to communicate with different levels of leadership conveying risk and driving urgency for risk remediation
Industry relevant professional certifications such as:
Ability to mentor and train team members to prioritize security efforts effectively
Experience testing modern applications in cloud-native tech stacks
Bachelor’s Degree required from an accredited, not for profit university or college (preferably in Computer Science/Cybersecurity)
A self-starter who can advance the application security program and follow-through ideas to completion
Minimum 1 to 3 years total experience in a technical role with at least 1 year of professional experience penetration testing
In-depth understanding of various assessment tools
Experience with common programming language: C# (preferred), Java, C/C++, Python, or Go
Experience writing comprehensive reports that clearly demonstrate the risk of vulnerabilities to developers and technical leadership
Experience coordinating with application teams to drive security by design principles
Offensive Security Certified Professional (OSCP) / Experienced (OSEP)
Hands-on experience implementing security tools into CI/CD pipelines
Demonstrate risk of detected issues to both technical and non-technical audiences
Experience with web application penetration testing, identifying and exploiting attack chains to evaluate the severity of vulnerabilities within a web application
Security tooling automation in CI/CD pipelines and IDE interfaces including Static Application Security Testing (SAST) and Static Application Analysis (SCA) solutions such as Veracode, CheckMarx, AppScan, X-Ray, Synopsys, or Snyk
INE Security Web Application Penetration Tester eXtreme (eWPTX)
Knowledge of infrastructure operations across databases, network, and system administration
Benefits
Access to CoStar Group’s Diversity, Equity, & Inclusion Employee Resource Groups
Life, legal, and supplementary insurance
Paid time off
On-site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes
Employee stock purchase plan
Virtual and in person mental health counseling services for individuals and family
Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks
401(K) retirement plan with matching contributions
Tuition reimbursement
Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
Commuter and parking benefits
Training + Development
Information not given or found
Interview process
Information not given or found
Visa Sponsorship
costar group is not able to provide visa sponsorship for this position.
Hey there! Before you dive into all the good stuff on our site, let’s talk cookies—the digital kind. We use these little helpers to give you the best experience we can, remember your preferences, and even suggest things you might love. But don’t worry, we only use them with your permission and handle them with care.