C

Senior Penetration Tester

cyberassurance United State
Remote
Apply
AI Summary

CyberAssurance seeks a Senior Penetration Tester to lead technical testing and social engineering engagements, identifying realistic attack paths and helping organizations become harder to compromise.

Key Highlights
Lead technical testing and social engineering engagements
Identify realistic attack paths and help organizations become harder to compromise
Conduct reconnaissance, exploitation, privilege escalation, lateral movement, and related testing activities
Key Responsibilities
Plan, lead, and execute technical testing and social engineering engagements
Conduct reconnaissance, exploitation, privilege escalation, lateral movement, and related testing activities
Produce clear reports explaining findings, business impact, exploitation, and recommended remediation
Technical Skills Required
Penetration testing Cybersecurity Threat modeling
Benefits & Perks
Competitive compensation
Paid time off and paid holidays
Health, dental, and vision insurance
Nice to Have
Experience with red teaming, adversary emulation, exploit development, reverse engineering, malware analysis, or mobile application testing
Experience working with financial institutions or other highly regulated organizations
Certifications such as OSCP, OSEP, OSCE, GPEN, GXPN, or similar offensive security credentials

Job Description


The Company: CyberAssurance is growing, and we’re looking for an experienced Senior Penetration Tester who wants to do more than run scans and produce reports.


CyberAssurance is built around the simple idea of Client-Centric Cyber: put the client first and give talented cybersecurity professionals the opportunity to do their best work. We focus on delivering clear, practical answers—not just technical findings—so clients understand what matters, why it matters, and what they should do next.


Our clients value CyberAssurance for our responsiveness, direct communication, technical expertise, and personalized service. We build long-term partnerships by consistently putting client needs first and maintaining a high standard of technical excellence.


The Role: This is a full-time, remote, hands-on, client-facing position for someone who enjoys thinking like an attacker, identifying realistic attack paths, and helping organizations become harder to compromise.

You’ll plan, lead, and execute technical testing and social engineering engagements including:

  • Internal and external network penetration testing
  • Web application and cloud penetration testing, including Azure and AWS
  • Microsoft 365 and Azure security assessments
  • Phishing, vishing, and onsite social engineering
  • Red team and purple team exercises


You’ll be expected to understand the environment, identify realistic attack paths, exploit weaknesses where appropriate, and demonstrate how individual vulnerabilities can be combined to create meaningful business risk. In addition you will:

  • Conduct reconnaissance, exploitation, privilege escalation, lateral movement, adversary emulation, and related testing activities.
  • Use open-source and custom-developed tools, modifying scripts and techniques when needed.
  • Perform application security testing, including web application testing, secure code review, and common exploit techniques.
  • Participate in advanced testing activities such as exploit development, reverse engineering, and malware or threat behavior analysis when appropriate to the engagement.
  • Produce clear reports explaining findings, business impact, exploitation, and recommended remediation, and lead client debriefs.
  • Collaborate with CyberAssurance consultants to develop practical remediation strategies for clients.
  • Help improve CyberAssurance methodologies, tools, documentation, and reporting while staying current with emerging vulnerabilities, threats, and attack techniques.
  • Provide technical guidance and mentoring to other team members as the penetration testing practice grows.


The Qualifications: we want someone who already knows how to penetrate environments and has demonstrated experience independently managing engagements from scoping through delivery.

Required qualifications include:

  • 5+ years of hands-on penetration testing experience, including senior or lead-level responsibilities.
  • Strong cybersecurity fundamentals, including threat modeling, vulnerability assessment, network security, Active Directory, application security, and secure architecture principles.
  • Experience with internal and external penetration testing, web applications, cloud environments, and multi-stage attack scenarios.
  • Proficiency with common offensive security tools and scripting experience.
  • Ability to produce technically accurate reports and clearly explain findings to both technical and nontechnical audiences.
  • Ability to independently manage engagements and priorities, work effectively with clients, and succeed in a remote environment, and deliver reports on time.
  • Travel up to 30% is required.
  • U.S. work authorization.

Preferred qualifications include:

  • Experience with red teaming, adversary emulation, exploit development, reverse engineering, malware analysis, or mobile application testing.
  • Experience working with financial institutions or other highly regulated organizations.
  • Certifications such as OSCP, OSEP, OSCE, GPEN, GXPN, or similar offensive security credentials.
  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.


About CyberAssurance: We aren’t trying to build the largest cybersecurity firm. We’re building a team of experienced professionals who take pride in their work, enjoy solving difficult problems, and want their contributions to matter.

At CyberAssurance, you’ll work directly with clients, have a voice in how engagements are conducted, help shape our testing methodologies, and work alongside experienced cybersecurity professionals.

What we offer:

  • Fully remote position
  • Competitive compensation
  • Paid time off and paid holidays
  • Health, dental, and vision insurance
  • Reimbursement for professional certifications
  • Paid training and continuing education opportunities
  • Conference and professional development support
  • Up to 30% travel is required for onsite penetration testing and social engineering engagements.

Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

limble

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

Emergent Software

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

prenuvo

United State

Subscribe our newsletter

New Things Will Always Update Regularly