Senior Penetration Tester
Full-time Not ApplicableJob Overview
What does this role do?
Conduct tactical assessments requiring expertise in application security (web and mobile), threat analysis, internal and external network architecture, and a wide array of commercial and custom products. Perform security research and publishing content to contribute to the information security community.
2
Configure and safely utilize attack tools and tactics against authorized targets. Develop scripts, automation frameworks, and security tools to enhance testing capabilities. Conduct AI-focused penetration testing and implement emerging security assessment methodologies.
3
Effectively communicate findings and strategic security recommendations to technical staff, executives, and legal counsel. Provide risk-appropriate guidance on vulnerability remediation and security best practices.
4
Support business units launching new applications and services by conducting comprehensive security assessments to identify risks of compromise or information leakage.
5
Write comprehensive formal security assessments using company standard reporting formats. Participate in client calls to review findings, discuss results, and provide remediation consultation and recommendations.
6
Retest resolved security vulnerabilities and update reports with verification results. Mentor junior pentesters on assessment methodologies, tools, technologies, and emerging security best practices. Drive process improvements, tool optimization, and automation
Skill 1
Network penetration testing; Web application penetration testing; Thick client application security assessment; Mobile penetration testing (iOS and Android); Cloud penetration testing (AWS, Azure, GCP);; AI security testing and vulnerability assessment.
Skill 2
Develop and modify exploits and security tools. Proficient in at least one programming language (Python, Java, Node.js). Proficient in scripting languages including Python, PowerShell, Bash. Experience building automation
Experience 3
Experience with Red, Blue, or Purple team exercises. Hands-on experience with network operating systems (Windows, Linux, macOS), network protocols, virtual environments, cloud platforms (AWS, Azure, GCP), containerized environments, and mobile operating systems (iOS, Android).
Competency 4
Familiarity with defensive technologies including firewalls, IPS/IDS, SIEM, EPP, EDR, UEBA, data encryption. Understanding of AI/ML security controls, secure development practices. Strong communication and stakeholder management skills with ability to mentor junior staff and translate technical findings for non-technical audiences and executives.
Competency 5
Understanding of OWASP, MITRE ATT&CK framework, software development lifecycle (SDLC). Knowledge of CI/CD pipelines, security automation, DevSecOps practices, and emerging security trends.
Make Your Resume Now