Application Security Testing Engineer
Job Description
Calance US is seeking an Application Security Testing Engineer to perform hands-on security testing of dynamic and web applications, leveraging tooling to identify vulnerabilities and guide remediation. This onsite role is based in Dallas, Texas.
Overview
A role centered on practical testing of dynamic and web-based applications, with an emphasis on security assessments and tooling integration.
Responsibilities
- Perform hands-on testing of web applications, including dynamic application security testing (DAST), targeted penetration testing, and Web Application Firewall (WAF) reviews.
- Manage vulnerability tooling and provide remediation guidance, plus debugging support via API.
- Utilize intercepting proxies such as Burp Suite and ZAP to inspect traffic and capture evidence.
- Apply Linux skills across testing environments to support assessment activities.
- Operate in a tool-agnostic manner with no specific development language preference, while understanding a developer's thought process.
Requirements
- Proficiency with Linux is required.
- Experience with intercepting proxies, specifically Burp Suite or ZAP, is required.
- Tool-agnostic approach with no particular development language preference; understanding of a developer's perspective is essential.
- Strong independence and the ability to work effectively in a resource-constrained environment.
Technologies
- Burp Suite
- ZAP
- Wireshark
- ServiceNow
- Tanium
- TPRM tooling
Engagement Details
Location: Dallas, TX onsite
Duration: 12 Months
Compensation: USD 75 - 85 per hour