Penetration Tester/Ethical Hacker
RegionUSA
SalaryUSD 110000
Job description
P enetration Tester / Ethical Hacker
About the Role
We are working with a client seeking a skilled Penetration Tester for a full-time, direct hire opportunity. This is a fully remote position open to candidates across the United States.
Responsibilities
- Plan and execute penetration tests across network, application, cloud, and social engineering attack surfaces
- Simulate real-world attack techniques to identify vulnerabilities before malicious actors do
- Conduct web application security assessments including OWASP Top 10 and beyond
- Perform internal and external network penetration testing and red team exercises
- Document findings clearly and thoroughly in professional reports tailored to both technical and executive audiences
- Communicate risk clearly — not just what was found, but what it means and how to fix it
- Collaborate with security and engineering teams to validate remediation of identified vulnerabilities
- Stay current on emerging attack techniques, tools, CVEs, and threat intelligence
- Contribute to the development of internal testing methodologies, playbooks, and tooling
Requirements
- 3+ years of experience in penetration testing or offensive security
- Proficiency with penetration testing tools — Metasploit, Burp Suite, Nmap, Cobalt Strike, or similar
- Strong understanding of network protocols, operating systems, and application architecture
- Experience with web application testing including API security assessment
- Familiarity with Active Directory attack paths and privilege escalation techniques
- Ability to write clear, professional penetration testing reports for both technical and non-technical audiences
- Strong understanding of common vulnerability classes and exploitation techniques
- Self-directed and able to manage engagements independently in a remote environment
Nice to Have
- Certifications — OSCP, CEH, GPEN, GWAPT, or similar offensive security credentials
- Experience with cloud penetration testing — AWS, Azure, or GCP environments
- Familiarity with red team operations and adversary simulation frameworks such as MITRE ATT&CK
- Experience with social engineering assessments including phishing simulations
- Knowledge of compliance frameworks — PCI-DSS, HIPAA, SOC 2, or FedRAMP
- Bug bounty participation or responsible disclosure history
- Scripting experience in Python, Bash, or PowerShell for custom tooling
Compensation
$110,000 — $150,000 base salary depending on experience. Full benefits package available.
Location
Fully remote — United States.
first seen 2026-08-13 16:48:01 · last verified 2026-08-14 14:48:02
pentestcareers.com // breach the job market