Conduct network, web application, and cloud penetration tests, red-team simulations, and vulnerability assessments, including exploit development and social engineering. Document findings and remediation guidance, verify fixes, and collaborate with defensive teams to improve SIEM monitoring and security alerts.
Relevant Experience Required: 3+ years of dedicated offensive security penetration testing and red teaming experience
Mandatory Certification: Offensive Security Certified Professional (OSCP) or GIAC Penetration Tester (GPEN)
Job Summary
We are seeking an experienced Penetration Tester to conduct rigorous, multi-vector offensive security assessments against our global network infrastructure, web applications, and cloud environments. The ideal candidate will emulate advanced persistent threat (APT) tactics, discover hidden exploit vulnerabilities, and write technical proof-of-concept reports to help software engineering and infrastructure teams systematically harden corporate defenses.
Key Responsibilities
Execute comprehensive network and web application penetration tests, utilizing automated scanning suites alongside manual exploration tactics to expose system vulnerabilities.
Conduct realistic red-teaming simulation campaigns, probing corporate defenses, orchestrating advanced social engineering scenarios, and bypassing physical perimeter monitoring configurations.
Develop structural custom exploitation scripts (e.g., Python, PowerShell, Bash) to demonstrate vulnerability severity while respecting operational stability guidelines.
Triage and evaluate cloud infrastructure entry vectors, assessing multi-tenant environment perimeters, microservice containers, API authentication weaknesses, and misconfigured access permissions.
Document and present highly detailed vulnerability disclosure reports, assigning clear impact scoring (CVSS), defining business risk matrices, and detailing step-by-step technical remediation paths.
Collaborate closely with blue-team defensive operators, providing specific threat behavior inputs to optimize SIEM monitoring rules and security log alerts.
Requirements
4 to 8 years of core cybersecurity technical experience, with 3+ dedicated years actively performing authorized penetration tests within enterprise frameworks.
Strong technical mastery of standard exploitation tooling arrays (e.g., Burp Suite Pro, Metasploit, Nmap, Kali Linux), reverse engineering scripts, and manual payload construction.
Deep structural understanding of the OWASP Top 10 web/API flaws, Windows/Linux kernel security architectures, privilege escalation techniques, and active directory exploit vectors.
Mandatory certification: OSCP or GPEN.
Preferred Qualifications
Offensive Security Certified Expert (OSCE) or Advanced Web Attacks and Exploitation (OSWE) credential.
Experience testing complex enterprise platforms like Salesforce networks, custom SAP endpoints, or specialized Workday database connectivity pipelines.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”