
Penetration Tester / Offensive Security Consultant
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in United States.
• Conduct penetration testing engagements focusing on infrastructure, networks, web applications, APIs, and more for clients.
• Evaluate Microsoft Active Directory, Entra ID, and associated identity and authentication environments.
• Detect attack paths, confirm security measures, and illustrate the real-world consequences of vulnerabilities.
• Execute application security assessments for web applications, services, APIs, mobile applications, and other client software.
• Engage in social engineering, wireless, cloud, and other specialized security evaluations.
• Create detailed professional reports that clarify technical findings, assess business risks, and provide actionable remediation advice.
• Interact directly with clients throughout the engagement process.
• Investigate emerging attack methods, technologies, tools, and defensive strategies.
• Construct, modify, or automate tools and workflows.
• Partner with colleagues to enhance services, methodologies, internal tools, and client experiences.
• Assume increasing responsibility, including leading intricate engagements, mentoring colleagues, refining methodologies, and creating new services.
• Practical experience in penetration testing, offensive security, application security, security research, systems administration, software development, artificial intelligence, or closely related technical fields.
• Solid understanding of common operating systems, networking principles, authentication technologies, and security measures.
• Familiarity with contemporary penetration testing methods and prevalent vulnerability categories.
• Capability to work remotely and independently, effectively manage time, and collaborate closely with teammates.
• Excellent written and verbal communication skills, including the ability to clarify technical topics to both technical and non-technical audiences.
• Consulting mindset, professional judgment, and a commitment to ethical and responsible security testing practices.
• An inquisitive nature and a willingness to learn.
• Openness to travel for on-site testing, client meetings, company events, and gatherings.
• OSCP or OSCE certification along with over 4 years of penetration testing experience would distinguish the candidate.
• Experience with Active Directory, Entra ID, Windows, Linux, web applications, APIs, cloud environments, or mobile applications.
• Familiarity with tools such as Burp Suite, CobaltStrike, Nmap, BloodHound, Impacket, NetExec, Metasploit, and other modern offensive security tools.
• Proficiency in software development or scripting using Python, PowerShell, C#, JavaScript/TypeScript, Go, or other relevant languages.
• Experience in developing exploits, modifying proof-of-concept code, reverse engineering, or circumventing security measures.
• Familiarity with AWS, Microsoft Azure, Microsoft 365, or other cloud and SaaS environments.
• Interest or experience in utilizing AI for security research, testing workflows, automation, analysis, or the development of offensive security capabilities.
• Evidence of hands-on curiosity through security research, CTF participation, lab environments, open-source contributions, or technical writing.
• Practical technical skills and experience are prioritized over specific certifications.
• Fully remote work opportunity.
• Chance to collaborate with a seasoned team of security consultants.
• Growth potential across various areas including infrastructure, applications, identity, cloud, social engineering, research, and offensive security.
• Opportunities to lead complex engagements, mentor team members, refine methodologies, and develop innovative services.
• Access to experiment with cutting-edge cybersecurity technologies.
• Opportunities to engage with automation, development, and AI-assisted approaches.
• Company events and meetings held approximately 2–3 times a year.
Shield AI
CI&T
Symphonic Distribution
Techdinamics Integrations Inc.
Get handpicked remote jobs straight to your inbox weekly.