Position Summary
Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.
Work you'll do
This role is responsible for providing penetration testing services through a combination of technology and manual ingenuity as part of the Global cyber services organization for member firms. Responsibilities of this role include: Executing Penetration testing engagements:Web Application Penetration TestingWeb Services / Application Programming Interface (API) Penetration TestingAI/LLM Penetration testingNetwork Penetration TestingMobile Application Penetration TestingThick Client Penetration TestingProviding consultative guidance to customers on findings identified in a clear and actionable fashion, both in writing and verballyEnhancing and updating testing methodologies, processes, and standards documentationLeveraging AI and LLM-based tools and prompt engineering, using both established platforms and emerging frameworks, to accelerate reconnaissance and generate or refine testing scriptsBuilding, customizing, and maintaining AI-driven agents to automate recurring testing tasksContinuously validating the accuracy and reliability of self-developed AI tools, actively working to reduce hallucinations and false positives in vulnerability identificationEvaluating and integrating emerging AI-assisted offensive security tooling into team methodology and playbooksProficient at analyzing and understanding complex architecture designs.Ability to effectively communicate the services and capabilities our group can facilitate to our clients. Professionals currently in a Deloitte Global role may be considered for this position, regardless of their US location.
The team
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Qualifications
Required: Experienced with Kali Linux or other dedicated Penetration Testing OS Platform. With knowledge of common testing tools like Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and othersFamiliarity with OWASP Top 10 software security weaknesses and vulnerabilitiesFamiliarity with various AI models and frameworks from providers such as Anthropic and OpenAI, and experience configuring tools like Obsidian and Ollama is a plus for supporting other workflows.Working knowledge of one scripting language and familiarity with at least one software programming language and frameworkDemonstrated experience working with diverse stakeholders, preferably on a global multi-national basisAbility to manage concurrent initiatives and use effective judgment in prioritization and time managementStrong written and verbal communication skillsMust be a US Citizen Preferred: Certified Ethical Hacker (CEH) CertificationOffensive Certified Security Professional (OSCP) CertificationAny GIAC Certification (GSEC, GWAB, GPEN, GMOB, GCPN)OWASP Application Security Top 10OWASP API Security Top 10OWASP Thick Client Top 10OWASP LLM Top 10MITRE ATT&CK FrameworkCloud Service testingReverse EngineeringStatic Application Software Testing (SAST)Dynamic Application Testing (DAST)Experience of Agentic development and its application to support penetration testingLimited immigration sponsorship may be available.
Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at
Recruiting tips
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Our people and culture
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.
Our purpose
Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more.
Professional development
From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
Requisition code:
Job ID
Same job available in 8 locations
Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.
Work you'll do
This role is responsible for providing penetration testing services through a combination of technology and manual ingenuity as part of the Global cyber services organization for member firms. Responsibilities of this role include: Executing Penetration testing engagements:Web Application Penetration TestingWeb Services / Application Programming Interface (API) Penetration TestingAI/LLM Penetration testingNetwork Penetration TestingMobile Application Penetration TestingThick Client Penetration TestingProviding consultative guidance to customers on findings identified in a clear and actionable fashion, both in writing and verballyEnhancing and updating testing methodologies, processes, and standards documentationLeveraging AI and LLM-based tools and prompt engineering, using both established platforms and emerging frameworks, to accelerate reconnaissance and generate or refine testing scriptsBuilding, customizing, and maintaining AI-driven agents to automate recurring testing tasksContinuously validating the accuracy and reliability of self-developed AI tools, actively working to reduce hallucinations and false positives in vulnerability identificationEvaluating and integrating emerging AI-assisted offensive security tooling into team methodology and playbooksProficient at analyzing and understanding complex architecture designs.Ability to effectively communicate the services and capabilities our group can facilitate to our clients. Professionals currently in a Deloitte Global role may be considered for this position, regardless of their US location.
The team
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Qualifications
Required: Experienced with Kali Linux or other dedicated Penetration Testing OS Platform. With knowledge of common testing tools like Burp Professional, AMASS, Metasploit, Postman, Swagger, NMAP, Qualys, SQL Map, and othersFamiliarity with OWASP Top 10 software security weaknesses and vulnerabilitiesFamiliarity with various AI models and frameworks from providers such as Anthropic and OpenAI, and experience configuring tools like Obsidian and Ollama is a plus for supporting other workflows.Working knowledge of one scripting language and familiarity with at least one software programming language and frameworkDemonstrated experience working with diverse stakeholders, preferably on a global multi-national basisAbility to manage concurrent initiatives and use effective judgment in prioritization and time managementStrong written and verbal communication skillsMust be a US Citizen Preferred: Certified Ethical Hacker (CEH) CertificationOffensive Certified Security Professional (OSCP) CertificationAny GIAC Certification (GSEC, GWAB, GPEN, GMOB, GCPN)OWASP Application Security Top 10OWASP API Security Top 10OWASP Thick Client Top 10OWASP LLM Top 10MITRE ATT&CK FrameworkCloud Service testingReverse EngineeringStatic Application Software Testing (SAST)Dynamic Application Testing (DAST)Experience of Agentic development and its application to support penetration testingLimited immigration sponsorship may be available.
Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at
Recruiting tips
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Our people and culture
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.
Our purpose
Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more.
Professional development
From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
Requisition code:
Job ID
Same job available in 8 locations
Penetration Tester in hermitage at Unknown Company
This position is listed as full time and onsite.