Senior Penetration Tester (US)

vuzekjiTRJmkGmmbvhsDMBยท Pen Testing
Apply Now โ†—
๐ŸŒ Remote๐Ÿ“ TELECOMMUTE๐Ÿ“ United StatesFull time

About this role

Company Description

BreachLock is a global leader in Offensive Security including Red Teaming, Continuous Attack Surface Discovery and Penetration Testing services. We help organizations discover, prioritize, and mitigate exposures with evidence-backed Attack Surface Management, Penetration Testing, and Red Teaming. BreachLock provides an attacker's perspective that goes beyond standard vulnerabilities, enabling organizations to build a comprehensive, proactive defense strategy.

ย 

Role Description

Penetration Tester (Mid-Senior)ย | Full-Time | Remote (US)

As a penetration tester on BreachLock's US Strategic delivery team, you'll execute manual, methodology-driven engagements across web applications, APIs, and internal networks โ€” including assumed breach simulations โ€” for enterprise clients. You'll work directly with delivery leadership, contribute to internal tooling and quality systems, and help raise the bar for the team around you.

ย 

Key Responsibilities

  • Execute web application, API and mobile penetration tests with a focus on manual testing beyond automated scanning โ€” business logic, authentication abuse, authorization flaws, and injection chains
  • Conduct internal network assessments, external network assessments and assumed breach engagements, including Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation
  • Leverage frameworks including MITRE ATT&CK, PTES, and OWASP to structure assessments and findings
  • Develop and contribute to internal tooling โ€” automation scripts, reporting utilities, and workflow improvements using Python, Bash, or similar
  • Participate in QA review cycles, providing structured feedback on findings, CVSS scoring accuracy, and report quality
  • Mentor junior testers through technical guidance and finding review
  • Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance
  • 3โ€“5 years of professional penetration testing experience in a delivery or consulting context
  • Strong web application and API testing fundamentals โ€” Burp Suite proficiency, OWASP Top 10 and beyond, authentication and session management testing
  • Solid internal network assessment skills โ€” AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, assumed breach methodology
  • Proficiency in scripting and automation (Python, PowerShell, Bash)
  • Strong written communication โ€” capable of writing clear, accurate, well-scoped findings independently
  • Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus
  • US-based and eligible to work without sponsorship

ย 

Preferred

  • Experience with C2 frameworks (Cobalt Strike, Havoc, Sliver, or similar)
  • Active involvement in cybersecurity communities, research, or bug bounty programs
  • Certifications such as OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent practical credentials
  • Experience with SIEM platforms or EDR tools from an adversarial perspective
  • Competitive compensation and performance-based equity opportunities
  • Flexible work hours with hybrid remote options
  • Opportunity to work with international cybersecurity experts
  • Strong career progression in a rapidly expanding early-stage company
  • Exposure to cutting-edge research, tools, and techniques in offensive security

ย 

Additional Organization Details

Frequently Asked Questions

Is the salary disclosed for the Senior Penetration Tester (US) position at vuzekjiTRJmkGmmbvhsDMB?
The salary for this Senior Penetration Tester (US) role at vuzekjiTRJmkGmmbvhsDMB is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Is the Senior Penetration Tester (US) job at vuzekjiTRJmkGmmbvhsDMB remote?
Yes, this Senior Penetration Tester (US) position at vuzekjiTRJmkGmmbvhsDMB is remote, with team members based in TELECOMMUTE, United States. You can work from home or anywhere in the supported regions.
Is the Senior Penetration Tester (US) role at vuzekjiTRJmkGmmbvhsDMB full-time or part-time?
This is listed as a Full time position. It is posted as a Senior Penetration Tester (US) role in the Pen Testing department at vuzekjiTRJmkGmmbvhsDMB.
Which team or department does the Senior Penetration Tester (US) at vuzekjiTRJmkGmmbvhsDMB belong to?
This Senior Penetration Tester (US) position is part of the Pen Testing department at vuzekjiTRJmkGmmbvhsDMB. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Senior Penetration Tester (US) position at vuzekjiTRJmkGmmbvhsDMB?
Click the "Apply Now" button on this page. You will be redirected to vuzekjiTRJmkGmmbvhsDMB's official application portal hosted on workable where you can submit your application directly.
When was the Senior Penetration Tester (US) job at vuzekjiTRJmkGmmbvhsDMB posted?
This Senior Penetration Tester (US) position at vuzekjiTRJmkGmmbvhsDMB was posted on May 25, 2026. Apply as soon as possible โ€” early applications are often reviewed first.
Senior Penetration Tester (US)
vuzekjiTRJmkGmmbvhsDMB
Apply for this role โ†—

You'll be redirected to vuzekjiTRJmkGmmbvhsDMB's official application page on workable.