Senior Offensive Security Consultant / Penetration Tester

REMINGTON ASSOCIATES LTD.
United States
23 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$125,000.0 - $160,000.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Application Programming Interfaces (APIs) Software System Penetration Testing Cloud Computing Fat Client Open Web Application Security Red Team (Cyber Security) Scripting Computer Networking Systems Mitre Att&ck

Job description

Who this role is for: You are an experienced penetration tester who prefers deep manual work over scanner-driven checklists. You enjoy chaining findings, building proof-of-concept tooling, thinking like an adversary, and explaining technical risk clearly. You understand that the test isn’t finished when the exploit lands, it’s finished when the client understands their risk and knows how to fix it.

The person we’re looking for: You combine technical depth with humility, curiosity, clear communication, strong judgment, and a bias toward practical solutions.

What You’ll Do

  • Lead manual penetration tests across network, web/API, cloud, wireless, thick client, and enterprise environments
  • Execute objective-based red team and adversary simulation engagements when in scope
  • Develop custom proof-of-concept exploits, scripts, and tradecraft when existing tools are not enough
  • Produce clear reports with attack narratives, evidence, business impact, and prioritized remediation guidance
  • Contribute to HALOCK methodology, tooling, lab work, research, and deliverables.
  • Participate in project kickoff and report delivery meetings
  • Mentor by example through sound judgment, clean execution, and professional communication
  • Support clients through remediation: answer follow-up questions, validate fixes, and help their teams understand not just what was found, but why it matters

Requirements

  • 5-7+ years of hands-on experience in penetration testing, offensive security consulting, or red team operations
  • Depth in at least one major domain, such as network, Active Directory, web/API, cloud, or red teaming
  • A skills-based certification or equivalent practical proof of ability
  • Proficient with common industry tools and C2 frameworks
  • Scripting or coding ability useful for automation, tooling, or exploitation
  • Working knowledge of PTES, OWASP, MITRE ATT&CK, and related offensive security references
  • Strong client-facing communication and ability to deliver with minimal supervision. You can walk a systems administrator through a finding, brief an executive on business risk, and listen well enough to understand a client’s environment and constraints before prescribing fixes

Bonus Points

  • Previous experience conducting penetration testing in a consulting capacity
  • Experience testing cloud, identity, EDR-protected endpoints, or mature enterprise networks
  • Ability to translate offensive security findings into compliance-relevant risk and remediation guidance
  • Experience with malware development, C2 framework enhancements, and EDR evasion
  • Desire to contribute to HALOCK’s blog and/or speak at industry conferences on occasion, * Penetration testing: 3 years (Preferred)

Benefits & conditions

$125,000 - $160,000 a year - Full-time, Pulled from the full job description

  • Paid training
  • Referral program
  • Professional development assistance
  • 401(k)
  • Health insurance
  • Retirement plan
  • Paid time off, At HALOCK Security Labs, we’re building an offensive security team for serious testers: technical, curious, practical, and focused on work that matters.

Our work is not tool-heavy checkbox testing. We think like adversaries, pursue meaningful attack paths, and turn technical evidence into decisions clients can act on. Our testers are consultants first. Our clients remember the testers who helped them actually remediate, and that’s the reputation we hire for.

What you can expect: remote-first work, challenging client environments, paid training and certifications, conference opportunities, experienced teammates, and room to improve methodology.

How We Work

We work as a high-trust, low-ego team that shares techniques, debriefs hard findings, challenges assumptions, and helps each other improve.

You will have room to go deep technically, improve methodology, contribute to research and tooling, and deliver work clients can rely on., HALOCK offers competitive compensation and benefits, including bonus potential, paid training and certifications, health and dental coverage, 401(k), long-term disability, conference attendance, and more.

Ready to apply? If this sounds like the work you want to do and the teammate you want to be, send your resume and a brief note about a challenging send your resume and a brief note about a challenging engagement you worked through and how you helped the client act on what you found.

Disclosures

  • HALOCK is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees.
  • Full background checks are performed, with consent, on all successful candidates before employment offers can be extended.
  • US citizens and Green Card holders, EAD and TN are encouraged to apply. We are unable to sponsor H1b candidates at this time.
  • No 3rd parties please. Only individuals need apply.

Pay: $125,000.00 - $160,000.00 per year, * 401(k)

  • Dental insurance
  • Health insurance
  • Paid time off
  • Professional development assistance
  • Referral program
  • Retirement plan

About the company

HALOCK Security Labs is a full-service information security consulting firm in Schaumburg, Illinois. Since 1996, we have provided technical security expertise and strategic advisement across penetration testing, red teaming, malware defense, incident response, risk, and compliance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber Ā· WWC Europe 2026

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders Ā· LIVE

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin Ā· WWC 2022

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper Ā· Europe 2026 Virtual

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser Ā· LIVE

4:30 min

Evaluating developer experience constraints in native scripts

Steve Shadders Ā· LIVE

Videos

See all

Related articles

See all