Quick Overview
Job Description
Senior Penetration Tester (Internal / External / Wireless / Cloud)
Location: Remote
1) About the Role
We're looking for a Senior Penetration Tester who can independently scope, lead, and execute offensive security engagements across internal, external, wireless, and cloud environments. This is a hands-on, engagement-ownership role you'll be the lead technical resource on fixed-scope, time-boxed assessments, from initial scoping calls through testing, reporting, and executive-level debriefs.
The ideal candidate has deep, real-world offensive security experience, is comfortable operating autonomously with minimal oversight, and can communicate findings clearly to both technical teams and executive stakeholders. Experience with cloud hardening assessments and emerging AI/LLM security testing is a strong plus, as our engagement scope continues to expand into these areas.
2) Key Responsibilities
- Independently scope, plan, and lead internal, external, wireless, and cloud penetration testing engagements end-to-end
- Conduct internal network penetration tests, including Active Directory attack path analysis and privilege escalation
- Perform external/perimeter penetration testing to identify internet-facing vulnerabilities and attack surface exposure
- Execute wireless security assessments (WPA2/WPA3, rogue AP detection, network segmentation testing)
- Conduct cloud hardening/hardiness assessments across AWS, Azure, and/or Google Cloud Platform identifying misconfigurations, IAM exposure, and attack surface risks
- Lead client scoping calls to define engagement objectives, rules of engagement, and testing boundaries
- Execute fixed-scope, time-boxed engagements autonomously, managing timelines and deliverables independently
- Produce clear, detailed, client-ready penetration testing reports with actionable remediation guidance
- Deliver executive debriefs, translating technical findings into business risk and impact for non-technical stakeholders
- Stay current on emerging attack techniques, tools, and threat landscape developments across traditional and cloud environments
- Where applicable, support AI readiness/guardrail assessments, including LLM security testing, prompt injection/red-teaming, and model governance framework evaluation
3) Requirements
- 6+ years of experience in offensive security, with demonstrated lead/senior-level engagement ownership
- Required certification (one or more): OSCP, OSCE/OSEP, GPEN or GWAPT, or OSWP (wireless)
- Proven track record independently scoping and executing internal, external, and wireless penetration tests end-to-end
- Hands-on experience conducting cloud hardening/hardiness assessments (AWS/Azure/Google Cloud Platform) misconfigurations, IAM exposure, attack surface review
- Strong background in Active Directory attack paths, perimeter/external testing, and wireless security assessments (WPA2/3, rogue AP, segmentation)
- Experience leading engagements for enterprise, SLED, or federal clients
- Demonstrated history of client-facing report writing and executive-level debriefs
- Proficiency with industry-standard offensive security tools: Burp Suite, Metasploit, Cobalt Strike, Nmap, BloodHound, Aircrack-ng/Kismet
- Able to work autonomously on fixed-scope, time-boxed engagements with minimal oversight
- Comfortable leading scoping calls and client debriefs directly
- Strong written and verbal communication skills across technical and executive audiences
4) Preferred Qualifications
- Experience with AI readiness/guardrail assessments LLM security testing, prompt injection/red-teaming, model governance frameworks
- Additional advanced certifications beyond the required set (e.g., holding more than one of OSCP/OSCE/OSEP/GPEN/GWAPT/OSWP)
- Experience testing federal or highly regulated environments (e.g., FedRAMP, StateRAMP, CMMC-adjacent engagements)
- Familiarity with purple team or adversary emulation frameworks (e.g., MITRE ATT&CK-aligned engagements)
- Prior experience mentoring junior penetration testers or contributing to methodology/playbook development
Similar jobs
- DS
Network Security Specialist with Security Clearance
NewData Systems Analysts, Inc. (DSA)
Charlottesville, VA🇺🇸$120k - $160k/yrOn-site21 hours ago - AC
Senior IT Security / IAM / SIEM-SOAR Production Support Engineer in Chandler, Arizona, or Charlotte, North Carolina (Hybrid)
NewAita Consulting Services,Inc.
Charlotte, NC🇺🇸Hybrid21 hours agoJiraManufacturing - KG
Security Engineering///Alpharetta ,GA//Fulltime, Onsite//In person Interview
NewK&K Global Talent Solutions
Milton, GA🇺🇸On-site21 hours agoAdministrative - IS
Saviynt Engineer
NewIlantus Services Private Limited
United States🇺🇸Hybrid21 hours agoEngineering - NT
Senior Information System Security Engineer (ISSE) with Security Clearance
NewNewGen Technologies
Lorton, VA🇺🇸Hybrid21 hours agoSQLSQL ServerSplunk+2Technology - TE
Network Engineer with Security Clearance
Tactical Engineering & Analysis, Inc.
Aiea, HI🇺🇸$120k - $150k/yrHybrid4 days agoAgileConfluenceJira+1Technology