penetration tester

Bishop Fox
Tempe, AZ, United States
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Working hours
Regular working hours

Tech stack

Password Cracking Java (Programming Language) JavaScript (Programming Language) Microsoft Windows Artificial Intelligence Amazon Elastic Compute Cloud Amazon S3 Apple Mac Systems Software System Penetration Testing User Authentication Cloud Computing Security Cyber Security
+18 more
Identity and Access Management Mobile Application Software Python (Programming Language) Network Security Linux System Administration Open Web Application Security Windows PowerShell Ruby Web Applications Large Language Models Software Security AWS Lambda Amazon Virtual Private Cloud (VPC) Information Technology Cloudwatch Vulnerability Analysis Golang Programming Languages

Job description

You’re a penetration tester who knows their way around source code. You’ve plundered apps and pillaged networks (legally, of course). You have a passion for hacking and information security. You may also have written a few blog posts about your favorite hacks or have presented at a handful of conferences - with an eye to doing more.

Requirements

  • 4+ years experience in planning, conducting, and managing web application penetration tests
  • 5+ years of application security experience
  • Deep understanding of security fundamentals (OWASP), common vulnerabilities, and application security best practices
  • Skilled in vulnerability assessment and the development of exploits for diverse targets
  • Background in system and network security, authentication and security protocols, and applied cryptography is helpful
  • Experience with programming and scripting languages such as Python, Ruby, PowerShell, Java, JavaScript, etc.
  • Bonus if you have experience reviewing Golang source code for vulnerabilities
  • Proficiency with operating systems- Linux, Windows, MacOS
  • Experience with network and system exploitation including modern tactics, techniques, and procedures (e.g. c2 frameworks, EDR bypass, privilege escalation, password cracking, lateral movement, etc.)
  • Strong technical reporting and documentation skills
  • Advanced relevant academic training, such as a degree in Computer Science or an OSCP, is a definite bonus
  • Experience with AWS cloud environments preferred with an understanding of its major technologies, such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambdas, and how to keep them secure
  • Secondary expertise in one or more of the following areas preferred: Cloud Security Assessments, Mobile Application Security Testing, Hybrid Application Assessments, or AI/LLM Security Assessments. Ability to communicate technical findings clearly to both technical and executive stakeholders, including actionable remediation guidance.

About the company

At Bishop Fox, security isn’t just a job-it’s our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation.

Joining Bishop Fox means collaborating with a curious and dedicated team. You’ll tackle complex challenges for some of the world’s most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions-including 16 open-source tools and 50 security advisories published in the past five years-we’re committed to making the digital world safer.

We’re looking for talented, experienced professional hackers to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US and internationally-based teams supporting clients across multiple industries., Bishop Fox has always allowed its employees to work remotely, and this role could work anywhere in the United States. Our comprehensive benefits program is tailored to meet your needs at an affordable price. We embrace diversity and an inclusive culture. We value our employees and who they are, which fosters a powerful and collective talent base to successfully serve our clients and the security community with unparalleled expertise.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.workingnomads.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

3:43 min

The enduring legacy of the amazon S3 storage API

Chris Heilmann +3 · LIVE

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

3:30 min

Falling in love with Ruby and creating Basecamp

David Heinemeier Hansson David Heinemeier Hansson +1 · Coffee With Developers

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

Videos

See all

Related articles

See all