Remote
Required Skills
5+ years of hands-on penetration testing experience, focused on web applications and APIs in enterprise environments
Demonstrated experience executing end-to-end penetration tests (scoping, exploitation, validation, reporting)
Strong working knowledge of web application vulnerabilities (e.g., OWASP Top 10, authentication/authorization flaws, injection attacks)
Proficiency with core security testing tools, including Burp Suite (advanced usage required), Nmap, and common exploitation frameworks
Experience writing scripts or automations in Python or Go to support testing workflows
Ability to clearly document findings with actionable remediation guidance for engineering teams
Experience partnering with engineering teams to validate and remediate vulnerabilities
Strongly Preferred
Experience testing mobile applications, hardware/embedded systems, or third-party/vendor platforms
Familiarity with PCI-related penetration testing requirements and compliance contexts
Experience contributing to or supporting bug bounty programs (triage, validation, escalation)
Exposure to threat modeling and ability to identify risk areas pre-deployment
Experience mentoring or providing technical guidance to other testers
Nice to Have
Advanced understanding of networking and system architecture in large-scale environments
Experience improving or automating penetration testing processes and tooling
Relevant certifications such as OSCP, OSCE, OSWE, or CISSP
Baseline Qualifications
Bachelor's degree in Computer Science, Cybersecurity, or equivalent practical experience
7+ years in cybersecurity, with progression in penetration testing responsibilities
Notes:
Remote