Remote job
Penetration Tester
Job details
About this role
Role overview
A hands-on offensive security role performing penetration tests across a variety of target classes for an independent security firm serving enterprise and public-sector clients. The work covers web, network, API, cloud, and mobile environments, with a strong emphasis on real manual exploitation, defensible methodology, and clear client-ready reporting.
Responsibilities
- Conduct penetration tests across more than one target class, including web, network, API, cloud, and mobile. - Perform manual exploitation rather than relying solely on automated scanner output. - Apply and adapt established methodologies (OWASP, PTES, NIST) when appropriate. - Produce clear, actionable reports that clients can use to drive remediation. - Feed findings, techniques, and lessons learned back into internal platforms and the broader research bench.
Requirements
- Solid hands-on testing experience across multiple target classes (web, network, API, cloud, or mobile). - Real manual exploitation ability, not just running and reading scanner results. - A methodology you can defend, with judgment to know when to deviate. - Clear written reporting skills; the report is the deliverable clients keep. - Demonstrated proof of capability, such as an OSCP or equivalent certification, a portfolio, public research, or a track record of relevant work.
Nice to have
- A deep specialty area such as cloud, mobile, hardware, or application logic exploitation. - Original research, a published CVE, or open-source offensive tooling. - Ability to learn new target types quickly.
Benefits and work setup
- Remote-first or in-office, with flexibility to choose the environment where you do your best work. - Independent company structure oriented around the work and the people it serves. - Slow, deliberate hiring with an emphasis on long-term retention. - Application process asks candidates to send work samples (a repo, write-up, tool, or track record) rather than a cover letter.