
Senior Penetration Tester
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in United States.
• Plan and carry out penetration testing initiatives across web applications, APIs, mobile applications, both internal and external infrastructures, and AWS cloud environments.
• Conduct offensive security operations, including red teaming and assumed-breach scenarios that encompass privilege escalation, lateral movement, persistence, and data exfiltration.
• Evaluate the security of cloud-native services, Kubernetes environments, microservices, and CI/CD pipelines.
• Identify vulnerabilities impacting payment systems, wallets, KYC/AML processes, bonus mechanisms, affiliate tracking, and other essential business workflows.
• Collaborate with Product, Engineering, AppSec, Payments, and Fraud teams to prioritize findings and facilitate remediation efforts.
• Create custom scripts and internal tools to enhance testing capabilities when standard solutions fall short.
• Participate in threat modeling activities and support secure-by-design initiatives.
• Review penetration testing strategies, reports, and provide technical guidance to junior and mid-level security professionals.
• Investigate emerging vulnerabilities, MITRE ATT&CK techniques, security advisories, and convert them into actionable enhancements.
• Assist in security assessments for new products, releases, and market launches, including effort estimation and pre-certification activities.
• Serve as a security advisor for both technical and business stakeholders regarding offensive security issues.
• Over 4 years of practical experience in penetration testing or offensive security.
• Demonstrated experience in at least three of the following areas:
• Web applications / APIs
• Internal networks
• External infrastructure
• Cloud environments (AWS/GCP)
• Mobile applications (iOS/Android)
• OSCP or an equivalent offensive security certification.
• Strong expertise in SAST, SCA, DAST, AWS/GCP, MITRE ATT&CK, OWASP ASVS, OWASP WSTG, and PTES.
• Good grasp of application architecture, including MVC and data flow principles.
• Familiarity with supply chain attack techniques.
• Proficient in writing scripts using Python and Bash.
• Understanding of IAM models within at least one major cloud provider.
• Practical experience testing Kubernetes-based environments, cloud-native applications, CI/CD pipelines (GitLab, GitHub Actions, Jenkins), and Infrastructure as Code solutions (Terraform, Helm, CloudFormation).
• Excellent reporting, documentation, and communication abilities.
• Capacity to balance security priorities with business and release timelines.
• Solid comprehension of security frameworks and compliance standards, including PCI DSS, ISO 27001, NIST, and GDPR.
• At least an Upper-Intermediate level of English proficiency.
• Generous annual leave along with paid sick leave.
• Comprehensive benefits package including private medical and dental insurance, sports allowance, and food vouchers.
• Support for professional development with an education budget and learning opportunities.
• Modern office environment with complimentary meals, snacks, and wellness initiatives for employees.
• Recognition programs, regular team events, and gifts for personal milestones.
IUNA AI
TEKsystems
Quest Global
McBride
Get handpicked remote jobs straight to your inbox weekly.