
Senior Penetration Tester
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in Michigan.
• Oversee penetration testing of both network and application infrastructures utilizing a combination of automated and manual methods.
• Detect vulnerabilities, assess risks, document results, and offer remediation advice.
• Manage comprehensive adversarial Red Team operations, covering scoping, rules of engagement, attack strategy, command-and-control infrastructure, multi-stage attack scenarios, operational security, evidence gathering, and reporting.
• Direct Threat Intelligence-driven Purple Team engagements alongside the Blue Team, ensuring effective validation of detection, response, and remediation efforts.
• Spearhead the retesting and validation processes for critical vulnerabilities.
• Aid in root cause analysis for security incidents and suggest corrective measures.
• Provide security expertise throughout various project lifecycles.
• Broaden offensive security knowledge and incorporate new tools, techniques, and methodologies into team operations and training.
• Mentor junior and mid-level penetration testers and lead technical training workshops.
• Create strategic reports, risk assessments, security recommendations, and executive summaries.
• Supervise IT Service Management workflows utilizing ServiceNow and Jira.
• Manage priorities, multiple projects, resources, and evolving security requirements.
• Stay informed about laws, regulations, compliance standards, and ethical principles.
• Perform additional duties as assigned.
• A Bachelor’s degree in Information Security, Computer Science, or a related discipline; equivalent experience may be considered in place of a degree.
• 6–8+ years of experience in penetration testing, red teaming, or a similar field.
• Proven success in leading complex assessments.
• In-depth understanding of Active Directory and Microsoft Entra ID architecture, including authentication, authorization, privilege escalation, security measures, and cross-environment attack strategies.
• Capability to design, construct, and maintain secure cloud-based command-and-control infrastructure.
• Extensive experience in developing and safely executing custom offensive capabilities for authorized adversary emulation.
• Familiarity with controlled payloads, post-exploitation tools, command-and-control integrations, and operational security.
• Advanced scripting and programming proficiency in Python, C, or PowerShell.
• Experience in automating testing processes.
• Proficient in using ServiceNow and Jira for documentation, tracking remediation, and optimizing workflows.
• Expertise in penetration testing tools and bespoke exploitation techniques.
• Comprehensive understanding of compliance requirements, ethical best practices, and regulations impacting penetration testing.
• Active engagement in pursuing advanced certifications and continual professional development.
• Preferred certifications include OSCP, CRTO, eWPTX, OSEP, OSWE, OSED, and OSCE3.
• Opportunities for professional development and training.
• Support for obtaining advanced certifications.
• Participation in mentoring and technical workshops.
• Commitment to equal employment opportunities.
Xflow
Addus HomeCare
alt.bank
NMDP
Get handpicked remote jobs straight to your inbox weekly.