
Penetration Tester
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in Philippines.
• Conduct thorough penetration tests across web, mobile, network, and system environments.
• Identify, exploit, and confirm vulnerabilities in critical infrastructure and applications.
• Generate technical reports detailing the impact of exploits and proof-of-concept sequences.
• Convert complex risk metrics into practical remediation roadmaps.
• Collaborate with client engineering teams for post-assessment remediation efforts.
• Address implementation challenges and validate applied fixes.
• Develop custom testing scripts, automation tools, and offensive strategies.
• Execute social engineering simulations, including targeted phishing and pretexting campaigns.
• Assist in incident response by examining compromise pathways and facilitating threat containment.
• Ensure transparent communication with clients and gather necessary environmental prerequisites.
• Monitor the evolving threat landscape and refresh assessment playbooks with the latest exploit techniques and defensive strategies.
• Demonstrated experience in conducting structured penetration tests, vector mapping, and threat validation across application, network, and system environments.
• Familiarity with industry-standard testing platforms, exploitation architectures, and reporting frameworks.
• Experience in exploiting, classifying, and cataloging multi-tier security vulnerabilities.
• Capability to generate high-quality assessment documentation, exploit-chain proofs, and comprehensive impact reports.
• Proficiency in communicating tactical risk scenarios and remediation expectations to both technical teams and executive stakeholders.
• Background in engineering custom testing scripts, phishing simulations, and pretexting campaigns.
• Advanced local testing station optimized for extensive virtual machine deployment.
• Availability to work during standard U.S. Eastern Time hours, from 8:00 AM to 5:00 PM ET.
• Possession of OSCP, CEH, or an equivalent offensive security credential, either actively held or in pursuit.
• Experience in cloud infrastructure penetration testing, container security assessments, or environment configuration audits in AWS, GCP, or Azure.
• Practical alignment of vulnerability data with SOC 2, GDPR, or HIPAA audit and evidence requirements.
• Experience enhancing offensive security workflows in fast-paced startups.
• Background in supporting incident response containment or designing technical employee threat-awareness programs.
• Exceptional written and verbal communication skills in English.
• Reliable high-speed internet connection and a professional home office setup.
• Willingness and capability to travel locally for occasional onsite meetings, team events, or business activities.
• Participation in live video interviews with camera on and identity verification during recruitment and onboarding processes.
• Successful completion of identity verification and background screening, where permitted by law.
• Opportunities for career development through mentorship and training.
• Reimbursement for the successful completion of approved role-related training and certification courses.
• Competitive base salary.
• Regular performance reviews linked to merit-based evaluations.
• Bonus opportunities.
• Significant potential for career advancement.
• Remote-first work flexibility.
• Chance to collaborate with a global team.
Acclaro
Dev.Pro
Halter
Applaudo
Get handpicked remote jobs straight to your inbox weekly.