> Markdown version of [/jobs/ext/1347620-senior-offensive-security-consultant-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1347620-senior-offensive-security-consultant-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Offensive Security Consultant / Penetration Tester - **Company:** REMINGTON ASSOCIATES LTD. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $125,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Software System Penetration Testing, Cloud Computing, Fat Client, Open Web Application Security, Red Team (Cyber Security), Scripting, Computer Networking Systems, Mitre Att&ck - **Published:** July 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d8920d1aa1a868a9 ## About the Role * 5-7+ years of hands-on experience in penetration testing, offensive security consulting, or red team operations * Depth in at least one major domain, such as network, Active Directory, web/API, cloud, or red teaming * A skills-based certification or equivalent practical proof of ability * Proficient with common industry tools and C2 frameworks * Scripting or coding ability useful for automation, tooling, or exploitation * Working knowledge of PTES, OWASP, MITRE ATT&CK, and related offensive security references * Strong client-facing communication and ability to deliver with minimal supervision. You can walk a systems administrator through a finding, brief an executive on business risk, and listen well enough to understand a client's environment and constraints before prescribing fixes Bonus Points * Previous experience conducting penetration testing in a consulting capacity * Experience testing cloud, identity, EDR-protected endpoints, or mature enterprise networks * Ability to translate offensive security findings into compliance-relevant risk and remediation guidance * Experience with malware development, C2 framework enhancements, and EDR evasion * Desire to contribute to HALOCK's blog and/or speak at industry conferences on occasion, * Penetration testing: 3 years (Preferred) ## Description Who this role is for: You are an experienced penetration tester who prefers deep manual work over scanner-driven checklists. You enjoy chaining findings, building proof-of-concept tooling, thinking like an adversary, and explaining technical risk clearly. You understand that the test isn't finished when the exploit lands, it's finished when the client understands their risk and knows how to fix it. The person we're looking for: You combine technical depth with humility, curiosity, clear communication, strong judgment, and a bias toward practical solutions. What You'll Do * Lead manual penetration tests across network, web/API, cloud, wireless, thick client, and enterprise environments * Execute objective-based red team and adversary simulation engagements when in scope * Develop custom proof-of-concept exploits, scripts, and tradecraft when existing tools are not enough * Produce clear reports with attack narratives, evidence, business impact, and prioritized remediation guidance * Contribute to HALOCK methodology, tooling, lab work, research, and deliverables. * Participate in project kickoff and report delivery meetings * Mentor by example through sound judgment, clean execution, and professional communication * Support clients through remediation: answer follow-up questions, validate fixes, and help their teams understand not just what was found, but why it matters ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)