
Associate Penetration Tester
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in Arizona, +18 more states.
• Validate security posture through penetration testing of systems within client networks.
• Conduct external penetration tests, which encompass reconnaissance, enumeration of internet-facing systems and services, vulnerability detection, reporting, and delivery to clients.
• Perform internal penetration assessments of client networks.
• Execute application penetration tests for client applications.
• Carry out social engineering assessments, including reconnaissance, campaign pretext design, phishing emails, spoofed login forms, reporting, and client delivery.
• Lead vulnerability assessments and provide remediation consulting.
• Conduct vulnerability scans, create scan reports, and offer remediation advice.
• Document testing methodologies, technical findings, proof-of-concept evidence, attack chains, and business impacts in professional reports.
• Stay updated on emerging threats, attack methods, tools, and industry trends through research, training, certifications, lab work, and knowledge sharing.
• Ensure compliance with internal quality standards, client confidentiality requirements, and OWASP, PTES, NIST, and MITRE ATT&CK frameworks and methodologies.
• Review reports from colleagues for formatting and narrative errors, providing constructive feedback.
• Collaborate with experienced security consultants.
• Occasionally work outside standard hours to cater to United States client time zones.
• Travel occasionally for on-site client engagements, projects, and team or company functions.
• An associate degree in a related field is required, or an equivalent combination of education, certification, and experience.
• A minimum of 1-2 years of experience managing IT systems in a professional setting is required.
• CEH, Net+, or a similar IT or security industry-recognized certification is preferred.
• General knowledge of networks, Linux systems, Windows systems, web applications, and scripting languages is essential.
• Familiarity with common attack tools, concepts, and frameworks used for reconnaissance, enumeration, vulnerability identification, exploitation, and reporting is necessary.
• Excellent verbal and written communication skills are required.
• Ability to effectively document technical findings, create client-ready deliverables, and present complex information in a professional manner.
• A demonstrated commitment to outstanding customer service and effective client relationship management is essential.
• Capability to translate technical security concepts, risks, and remediation suggestions for business stakeholders and non-technical audiences is necessary.
• Strong analytical and critical-thinking abilities are required.
• Ability to assess security vulnerabilities, validate findings, and propose practical risk mitigation strategies is essential.
• Effective organizational and time management skills are necessary.
• Ability to handle multiple projects and competing deadlines while maintaining attention to detail is required.
• Proficiency with all Microsoft Office Suite products is essential.
• Must reside in one of the designated United States states.
• Flexible work schedules and options for remote or hybrid work.
• Employee Assistance Program (EAP).
• Support for mental wellbeing.
• Ongoing learning and professional development opportunities.
• Medical, dental, and vision insurance.
• Options for health savings, flexible savings, and dependent care savings accounts.
• Life and disability insurance.
• 401(k) plan with employer matching up to 4%.
• Pet insurance.
• Unlimited paid time off.
• Paid parental leave: 6 weeks for non-birthing parents and 12 weeks for birthing parents at 100% regular, straight-time weekly pay.
• 11 paid holidays.
• Volunteer time off.
• Flexibility in working hours outside of scheduled meetings.
• Minimal travel required, less than 5%.
Step-Up
Testlio
Clario
Shopware
Get handpicked remote jobs straight to your inbox weekly.