Penetration Tester
Job description
Job Summary The Penetration Tester is an entry-level practitioner who executes scoped engagements under supervision, with the expectation of self-sustainment without supervision following the completion of a 90-day probationary period.
All Penetration testers are expected to follow Fortifieds established penetration testing methodology across network, system, and application targets.
This role is responsible for accurately and thoroughly documenting findings and outcomes for formal reports and client deliverables.
Client-facing communications are produced under supervision and reviewed by a qualified peer or the manager before delivery, ensuring quality and consistency at every stage.
The Penetration Tester develops foundational exploitation skills across a range of attack surfaces, demonstrates awareness of social engineering concepts and their role in penetration testing engagements, and is expected to actively pursue certification as a signal of professional commitment.
This role requires effective written and verbal communication, adherence to rules of engagement, and a commitment to continuous improvement in technique and documentation quality.
Essential Job Functions The following duties are normal for this position.
The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position.
Other duties may be required.
Executes scoped penetration testing engagements under supervision, including internal, external, wireless, and application targets, following Fortifieds established methodology throughout.
Produces accurate and well-documented findings including formal reports, notes, presentations, and appendices, delivered within project schedule and reviewed by an IC2 or IC3 practitioner before client submission.
Reports project performance metrics to the Penetration Testing Manager or assigned IC2/IC3 lead; flags delivery risks or blockers proactively.
Maintains foundational awareness of current network, system, and application threats, vulnerabilities, and exploitation techniques; actively develops technical depth over time.
Actively pursues relevant industry certifications; eJPT or CEH expected as an entry baseline with OSCP targeted within 18 months of hire as a near-term professional development goal.
Demonstrates working familiarity with penetration testing tools including Kali Linux, Metasploit, NMAP, Burp Suite (Community), and Nessus; continues developing proficiency through hands-on engagement work.
Applies penetration testing methodologies including OWASP, PTES, NIST SP800-115, and MITRE ATT&CK under supervision; builds understanding of how methodology selection and scope definition affect engagement outcomes.
Maintains working knowledge of networking technologies, protocols, and network functionality as they apply to penetration testing scope and attack surface analysis.
Follows Fortifieds rules of engagement and operating procedures to detect, identify, and exploit vulnerabilities across operating systems, applications, and hardware, with minimal impact on client operations.
Works effectively within a team environment; communicates clearly with assigned IC2 or IC3 oversight on engagement status, blockers, and findings during active projects.
Delivers routine client status updates on a daily or weekly cadence as directed; all client communications are reviewed and validated by an IC2 or IC3 practitioner prior to delivery during the first 90 days and until independent communication readiness is confirmed.
Accurately enters and submits time by required deadlines.
Routinely checks and responds to communications from Fortified personnel; participates in mandatory company training and team and departmental meetings.
Books travel in adherence to company and client travel policy.
Maintains detailed documentation of customer interactions, engagement actions, and testing notes throughout each assigned project.
Demonstrates awareness of social engineering concepts and their role in penetration testing engagements; supports social engineering components within defined engagement scope as directed.
Maintains familiarity with Fortifieds core service offerings and makes appropriate client recommendations based on those offerings.
Knowledge & Skills Education & Experience Bachelors degree in Computer Science, Information Technology, Cybersecurity, or equivalent hands-on experience.
Minimum of 2 years of experience in security or IT; lab-based experience and CTF participation accepted at entry level.
Healthcare IT experience is a plus.
Strong computer skills in Adobe and Microsoft Office applications (Project, Visio, Word, Excel, PowerPoint).
Solid understanding of hardware and networking terminology and devices.
Special Skills & Knowledge Experience with network security, topology, networking technologies and an understanding of the OSI Model.
Thorough understanding of the latest security principles, techniques, and protocols.
Familiarity with generating and troubleshooting PowerShell/bash/python scripts.
Ability to work and communicate effectively, positively, and professionally with clients, third-party system vendors, and other departments.
Must possess a level of professionalism and diplomacy that will serve to build and maintain relationships throughout the project and beyond.
Excellent interpersonal skills that include the ability to communicate verbally and in writing effectively.
Resourcefulness and ability to take the initiative in developing and completing work projects.
Must possess and have proven problem-resolution / critical thinking skills.
Must be flexible and work with a high level of initiative.
Ability to retain and protect confidential material.
Licenses, Certifications, etc.
eJPT or CEH required as entry baseline; OSCP strongly preferred and expected to be actively pursued within 18 months of hire active pursuit of OSCP is a readiness signal for promotion consideration.
Foundational technical skills in Kali Linux, Metasploit, and Burp Suite (Community); basic scripting in Python or Bash; foundational understanding of social engineering tactics and their application in engagement contexts.
Requirements Supervisory Responsibility N/A Working Conditions & Travel Requirements Evenings and weekend hours should be anticipated.
Travel as needed.
Fortified Health Security is an Equal Opportunity Employer.
In compliance with the Americans with Disabilities Act, Fortified Health Security will provide reasonable accommodations to qualified individuals with disabilities.
If a reasonable accommodation is needed to perform this position, you need to inform Fortified Health Security People and Culture Team of such request.
Signatures below indicate the receipt and review of this job description by the associate assigned to the position and the People and Culture Team.
first seen 2026-07-23 20:48:01 · last verified 2026-07-23 20:48:01
pentestcareers.com // breach the job market