Lead Application Penetration Tester

Post Date

Sep 25, 2025

Location

Washington,
District Of Columbia

ZIP/Postal Code

20002
US
Nov 30, 2025 Insight Global

Job Type

Perm

Category

Security Engineering

Req #

JAX-4eba3dc1-ca61-4e34-b6e2-b0130e50f2b5

Pay Rate

$160k - $180k (estimate)

Job Description

Insight Global’s client is looking for a Lead Application Security Penetration Tester to join their team in Washington, DC. This person will work closely in a team of 5 individuals doing source code review and penetration testing to identify any security concerns or vulnerabilities within mobile applications. You will be testing security within a microservices based environment and performing some red team responsibilities. Also, you will be responsible for conducting assessments and providing documentation of the findings.
Compensation: $160,000 - $180,000 per year

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Required Skills & Experience

• 7+ years of experience conducting manual Source Code reviews.
• Experience with automated testing tools for SAST (Static Application security Testing), DAST (dynamic Application security Testing), and SCA (software Composition Analysis)
o Example tools: Checkmarx, Burp Suite Pro, Plextrac, Veracode, Hashicorp Vault
• Experience with hands on manual penetration testing
o Example tools: Synapsis, Veracode
• Experience with web application and API testing
o Example tools: Postman, SmartBear, SoapUI Experience with mobile testing (ios and android) with tools such as Corellium or similar
• Experience testing within a cloud environment Proficient reading and/or coding in multiple programming languages
• Experience with testing within Cloud environments
• Excellent verbal & written communication as this person will be reporting findings to various stakeholders.

Nice to Have Skills & Experience

- Bachelors degree in computer science or related field
- Security certifications such as:
o GWAPT
o CEH
o OSCP

Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.