Job description
Job Description: - Provide security posture validation through penetration testing of systems on client networks
- Execute external penetration tests, including reconnaissance, enumeration of internet-facing systems and services, vulnerability identification, reporting, and client delivery
- Conduct internal penetration tests of client networks
- Perform application penetration tests of client applications
- Execute social engineering tests, including reconnaissance, campaign pretext design, phishing emails, spoofed logon forms, reporting, and client delivery
- Lead vulnerability assessments and remediation consulting
- Perform vulnerability scans, generate scan reports, and advise on remediation
- Document testing methodologies, technical findings, proof-of-concept evidence, attack chains, and business impact in professional reports
- Stay current on emerging threats, attack techniques, tools, and industry trends through research, training, certifications, lab work, and knowledge sharing
- Maintain compliance with internal quality standards, client confidentiality requirements, and OWASP, PTES, NIST, and MITRE ATT&CK frameworks and methodologies
- Review colleagues’ reports for formatting and narrative errors and provide feedback
- Work alongside experienced security consultants
- Periodically work outside standard hours to accommodate United States client time zones
- Occasionally travel for on-site client visits, projects, and team or company activities
Requirements: - Associates degree in related field required, or equivalent combination of education, certification and experience
- Minimum of 1-2 years of experience managing IT systems in a professional environment required
- CEH, Net+ or similar IT or security industry recognized certification preferred
- General knowledge of Networks, Linux systems, Windows systems, web applications, and scripting languages
- Familiarity with common attack tools, concepts, and frameworks used for reconnaissance, enumeration, vulnerability identification, exploitation, and reporting
- Excellent verbal and written communication skills
- Ability to clearly document technical findings, develop client-ready deliverables, and present complex information professionally
- Demonstrated commitment to exceptional customer service and effective client relationship management
- Ability to translate technical security concepts, risks, and remediation recommendations for business stakeholders and non-technical audiences
- Strong analytical and critical-thinking skills
- Ability to evaluate security weaknesses, validate findings, and recommend practical risk mitigation strategies
- Effective organizational and time management skills
- Ability to manage multiple projects and competing deadlines while maintaining attention to detail
- Proficient with all Microsoft Office Suite products
- Must be located in one of the specified United States states
Benefits: - Flexible schedules and remote or hybrid work options
- Employee Assistance Program (EAP)
- Mental wellbeing support
- Ongoing learning opportunities and professional development support
- Medical, dental and vision insurance
- Health savings, flexible savings and dependent care savings account options
- Life and disability insurance
- 401(k) with employer match up to 4%
- Pet insurance
- Unlimited paid time off
- Paid parental leave: 6 weeks for non-birthing parents and 12 weeks for birthing parents at 100% regular, straight time weekly pay
- 11 paid holidays
- Volunteer time off
- Flexible working schedule outside scheduled meetings
- Minimal travel, less than 5%
first seen 2026-09-11 17:30:01 · last verified 2026-09-11 21:30:01
pentestcareers.com // breach the job market