Haystack
← Back to Jobs
Remote
Engineering

Penetration Testing Engineer

GDHUnited States🇺🇸United StatesPosted 31 Jul 2026

Quick Overview

Salary
$80 - $88/hr
Work Type
Remote
Level
Mid Senior

Job Description

Role Summary
This position is a senior-level offensive security analyst responsible for planning, executing, and overseeing penetration testing activities across web applications, APIs, networks, and cloud infrastructure. The role involves leading internal and third-party security assessments, analyzing findings, and driving remediation efforts to enhance the organization’s security posture. Collaboration with cross-functional teams and continuous improvement of testing methodologies are key components of this role.

Responsibilities

  • Develop and execute comprehensive offensive security test plans for web applications, APIs, networks, and cloud environments.
  • Retest and validate remediated vulnerabilities to ensure gaps are effectively closed.
  • Support the scoping, oversight, and management of internal and third-party security testing engagements.
  • Create detailed, actionable reports with clear remediation guidance targeting technical teams and leadership.
  • Track and analyze security trend data, including recurring vulnerabilities and time-to-remediate metrics, to inform program priorities.
  • Collaborate with engineering, security, and governance teams to drive vulnerability remediations and validate security findings.
  • Assist in meeting compliance requirements through targeted testing and security assessments.
  • Contribute adversary perspective inputs into threat modeling, architecture reviews, and secure coding standards.
  • Maintain and refine internal testing playbooks, leveraging AI and other automation tools to enhance workflows.
  • Mentor team members on offensive techniques, attack tools, and adversarial thinking, staying current on emerging threats and attack methods.

Qualifications

  • 5-7+ years of hands-on offensive security or penetration testing experience in web, network, and cloud environments.
  • Proven experience leading or maturing an offensive security program or methodology.
  • Skilled in scoping and managing internal and third-party security engagements, including rules of engagement.
  • Expert in offensive security tools such as Burp Suite, Kali Linux, and manual exploitation techniques.
  • Hands-on experience with Active Directory and internal network exploitation (e.g., Kerberoasting, privilege escalation).
  • Working knowledge of cloud attack surfaces, including IAM, container security, and CI/CD pipeline attacks.
  • Experience utilizing AI tools to accelerate security workflows.
  • Deep understanding of OWASP Top 10, MITRE ATT&CK, CVSS, and attack chain thinking.
  • Proficiency in scripting and automation (Python, Bash, Powershell).
  • Experience with threat modeling frameworks like STRIDE or PASTA.
  • Ability to securely handle and report sensitive engagement data.
  • Strong communication skills, capable of explaining complex security issues to diverse audiences.
  • Self-motivated team player with enthusiasm for learning and professional growth.

Qualifications (Preferred)

  • Bachelor’s degree in Computer Science, Software Engineering, or related field, or equivalent experience.
  • Relevant certifications such as OSCP, OSWE, OSEP, or equivalent red-team credentials.
  • Cloud security certifications (AWS, Azure, GCP).
  • Experience with C2 frameworks and adversary emulation.
  • Familiarity with SIEM/EDR and detection engineering.
  • Background in exploit development or evasion tooling (C/C++, JavaScript, Go, Python).
  • Knowledge of SAST, DAST, SCA, and vulnerability management tools.
  • Experience building or maintaining offensive security playbooks.
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001.
  • In compliance with federal law, all persons hired must verify their identity and eligibility to work in the United States and complete the required employment eligibility verification form upon hire. Candidates must be legally authorized to work in the United States without employer sponsorship, now or in the future.
     

Publishing Pay Range: $80.00 - $88.00 hourly
This is a fully remote role and can be performed from an approved location.

Similar jobs