Penetration Tester / Security Assessor — Cyber Threat Intelligence
Job description
Team: Cyber Threat Intelligence (SecOps) - This team is made up of highly motivated senior cybersecurity practitioners who bring deep hands-on experience in penetration testing, assessment, threat hunting, forensics, and security operations
- The team works closely together to support ongoing security testing initiatives, validate risk across applications and infrastructure, and help strengthen the organization's overall security posture
- A key selling point for candidates is the team's collaborative culture, with members openly sharing intelligence, techniques, and findings and actively supporting one another in solving complex security problems
- This is a strong opportunity for someone who values working alongside experienced professionals in an environment that encourages knowledge sharing, continuous learning, and high-quality security work
Required Skills - Linux
- Various penetration testing tools (BurpSuite, MetaSploit, Nessus)
Day to Day - A penetration tester / security assessor typically spends the day planning and executing security tests against applications, systems, and infrastructure to uncover vulnerabilities before attackers do
- Much of the work involves using Linux-based environments and tools such as Burp Suite, Metasploit, and Nessus to perform web application testing, vulnerability scanning, exploitation validation, and manual verification of findings
- They often review scope, analyze prior results, run scans, investigate weaknesses, and document evidence to determine real-world risk
Soft Skills - Strong verbal and written communication skills, with the ability to clearly explain security findings to both technical teams and non-technical stakeholders
- Ability to translate complex vulnerabilities into business-relevant risk and provide practical, understandable remediation guidance
- Professional presence and confidence when discussing assessment results, answering questions, and presenting recommendations
- Ability to document findings thoroughly, accurately, and in a polished manner suitable for reports and stakeholder communication
Not Looking For - Someone whose experience is limited to running automated vulnerability scans without being able to validate, exploit, or explain the findings
- A candidate who relies entirely on tools like Nessus and cannot perform manual penetration testing against applications, systems, or infrastructure
- Someone who cannot distinguish false positives from legitimate security weaknesses or assess real-world risk
- A security analyst with only compliance or checklist-based assessment experience in place of hands-on penetration testing expertise
first seen 2026-09-22 13:30:01 · last verified 2026-09-28 17:30:01
pentestcareers.com // breach the job market