Penetration Tester

DeepSeas

$95K — $115K *
US-AnywhereRemote in United States
Technical Services
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2-5 years of experience in penetration testing or offensive security; equivalent skills considered.
  • Proficient with tools like Nmap, Metasploit, Burp Suite, and Nessus/OpenVAS.
  • Solid grasp of networking fundamentals and common vulnerability classes.
  • Familiar with at least one scripting language for automation (Python, Bash, PowerShell).
  • Exposure to cloud platforms and common misconfiguration patterns.
  • Understanding of AI technology application in security.
  • Strong written communication skills for producing professional documentation.

Responsibilities

  • Conduct internal and external network penetration tests to identify vulnerabilities.
  • Perform web application assessments based on OWASP Top 10 and API testing standards.
  • Execute basic cloud security assessments including misconfigurations and IAM reviews.
  • Engage in adversarial testing methods such as red team and purple team exercises.
  • Support AI security assessments, including prompt injection and threat scenarios, under senior guidance.
  • Produce detailed, client-ready reports with technical narratives and remediation advice.
  • Participate in client meetings to communicate findings and maintain collaborative relationships.

Benefits

  • Continuous training and development opportunities.
  • Potential travel requirements (up to 25%).
  • Remote work flexibility within the United States.
Full Job Description
Penetration Tester

Department: Offensive Security

Employment Type: Full Time

Location: Remote - United States

Description

The Penetration Tester is a practicing offensive security professional who independently executes client engagements across DeepSeas' core service lines. This role represents the transition from emerging practitioner to confident, self-sufficient contributor. Penetration Testers own their engagements end-to-end within defined scope, produce client-ready deliverables without heavy oversight, and are developing the depth and breadth needed to tackle increasingly complex environments. This is the primary delivery role on the team and the foundation of the practice's capacity.

Key Responsibilities

Technical Delivery
  • Conduct internal and external network penetration tests including enumeration, exploitation, lateral movement, and post-exploitation within defined scope.
  • Perform web application assessments aligned to OWASP Top 10 and API security testing standards.
  • Conduct basic cloud security assessments (AWS, Azure, GCP) including misconfiguration identification, IAM review, and exposed services enumeration.
  • Bring experience with adversarial engagements such as red team and purple team exercises.
  • Support AI/LLM security assessments including prompt injection, model abuse scenarios, and OWASP LLM Top 10 coverage under senior guidance.

Reporting & Client Communication
  • Produce complete, client-ready findings reports with clear technical narratives, reproduction steps, risk ratings, and remediation guidance.
  • Participate in client kick-off calls and debrief walkthroughs, communicating findings professionally to technical and non-technical stakeholders.
  • Maintain accurate engagement documentation, time tracking, and artifact organization in project management systems.

Professional Growth & Travel
  • Pursue continuous development through assigned training, lab environments, and certification advancement.
  • May be required to travel up to 25% of the time.
  • Candidates must be U.S. citizens and currently reside within the United States.


Skills Knowledge and Expertise

Minimum Qualifications
  • 2-5 years of professional penetration testing or applied offensive security experience; strong candidates with equivalent demonstrated skills will be considered.
  • Proficiency with standard toolsets: Nmap, Metasploit, Burp Suite, Nessus/OpenVAS, BloodHound, or equivalents.
  • Solid understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, AD, VPNs) and common vulnerability classes.
  • Familiarity with at least one scripting language (Python, Bash, or PowerShell) for basic automation and tooling.
  • Exposure to cloud platforms (AWS, Azure, or GCP) and awareness of common cloud misconfiguration patterns.
  • Solid understanding of AI technology in everyday work activities.
  • Strong written communication with the ability to produce accurate, professional-quality findings documentation.

Preferred Qualifications
  • Hands-on penetration testing certification, such as PNPT (TCM Security), OSCP (Offensive Security), CompTIA PenTest+, or eWPT/eJPT with demonstrated experience.

Similar Jobs

More Jobs at DeepSeas

  • Penetration Tester
    $95K — $115K *
    San Diego, CA 92154 (San Diego County)
    Information Technology
    In-Person
  • Penetration Tester
    $95K — $115K *
    Remote
    Technical Services
    Remote in United States

More Technical Services Jobs

Find similar Penetration Tester jobs: