Senior Offensive Security Consultant / Penetration Tester
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Who this role is for: You are an experienced penetration tester who prefers deep manual work over scanner-driven checklists. You enjoy chaining findings, building proof-of-concept tooling, thinking like an adversary, and explaining technical risk clearly. You understand that the test isnāt finished when the exploit lands, itās finished when the client understands their risk and knows how to fix it.
The person weāre looking for: You combine technical depth with humility, curiosity, clear communication, strong judgment, and a bias toward practical solutions.
What Youāll Do
- Lead manual penetration tests across network, web/API, cloud, wireless, thick client, and enterprise environments
- Execute objective-based red team and adversary simulation engagements when in scope
- Develop custom proof-of-concept exploits, scripts, and tradecraft when existing tools are not enough
- Produce clear reports with attack narratives, evidence, business impact, and prioritized remediation guidance
- Contribute to HALOCK methodology, tooling, lab work, research, and deliverables.
- Participate in project kickoff and report delivery meetings
- Mentor by example through sound judgment, clean execution, and professional communication
- Support clients through remediation: answer follow-up questions, validate fixes, and help their teams understand not just what was found, but why it matters
Requirements
- 5-7+ years of hands-on experience in penetration testing, offensive security consulting, or red team operations
- Depth in at least one major domain, such as network, Active Directory, web/API, cloud, or red teaming
- A skills-based certification or equivalent practical proof of ability
- Proficient with common industry tools and C2 frameworks
- Scripting or coding ability useful for automation, tooling, or exploitation
- Working knowledge of PTES, OWASP, MITRE ATT&CK, and related offensive security references
- Strong client-facing communication and ability to deliver with minimal supervision. You can walk a systems administrator through a finding, brief an executive on business risk, and listen well enough to understand a clientās environment and constraints before prescribing fixes
Bonus Points
- Previous experience conducting penetration testing in a consulting capacity
- Experience testing cloud, identity, EDR-protected endpoints, or mature enterprise networks
- Ability to translate offensive security findings into compliance-relevant risk and remediation guidance
- Experience with malware development, C2 framework enhancements, and EDR evasion
- Desire to contribute to HALOCKās blog and/or speak at industry conferences on occasion, * Penetration testing: 3 years (Preferred)
Benefits & conditions
$125,000 - $160,000 a year - Full-time, Pulled from the full job description
- Paid training
- Referral program
- Professional development assistance
- 401(k)
- Health insurance
- Retirement plan
- Paid time off, At HALOCK Security Labs, weāre building an offensive security team for serious testers: technical, curious, practical, and focused on work that matters.
Our work is not tool-heavy checkbox testing. We think like adversaries, pursue meaningful attack paths, and turn technical evidence into decisions clients can act on. Our testers are consultants first. Our clients remember the testers who helped them actually remediate, and thatās the reputation we hire for.
What you can expect: remote-first work, challenging client environments, paid training and certifications, conference opportunities, experienced teammates, and room to improve methodology.
How We Work
We work as a high-trust, low-ego team that shares techniques, debriefs hard findings, challenges assumptions, and helps each other improve.
You will have room to go deep technically, improve methodology, contribute to research and tooling, and deliver work clients can rely on., HALOCK offers competitive compensation and benefits, including bonus potential, paid training and certifications, health and dental coverage, 401(k), long-term disability, conference attendance, and more.
Ready to apply? If this sounds like the work you want to do and the teammate you want to be, send your resume and a brief note about a challenging send your resume and a brief note about a challenging engagement you worked through and how you helped the client act on what you found.
Disclosures
- HALOCK is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees.
- Full background checks are performed, with consent, on all successful candidates before employment offers can be extended.
- US citizens and Green Card holders, EAD and TN are encouraged to apply. We are unable to sponsor H1b candidates at this time.
- No 3rd parties please. Only individuals need apply.
Pay: $125,000.00 - $160,000.00 per year, * 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Professional development assistance
- Referral program
- Retirement plan
About the company
HALOCK Security Labs is a full-service information security consulting firm in Schaumburg, Illinois. Since 1996, we have provided technical security expertise and strategic advisement across penetration testing, red teaming, malware defense, incident response, risk, and compliance.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role ā technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Dev Digest 191: Malware interviews, EU ā¤ļø Open Source and Skilled Agents
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.