Penetration Tester

DUNHILL PROFESSIONAL SEARCH
United States
6 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$90,000.0 - $109,000.0
Working hours
Regular working hours

Tech stack

HTML JavaScript (Programming Language) Microsoft Windows Apple Mac Systems Software System Penetration Testing Bash Shell Burp Suite Cyber Security Cross-Site Request Forgery Linux Domain Name System (DNS) Hypertext Transfer Protocols (HTTP)
+20 more
Virtual Private Networks (VPN) Information Systems Security Architecture Professional Python (Programming Language) Network Protocols Open Web Application Security Windows PowerShell Ruby SQL Injection SQL Databases TCP/IP Web Applications Network Routers Scripting Firewalls (Computer Science) Cross-Site Scripting (XSS) Information Technology Metasploit Web Technologies Vulnerability Analysis Programming Languages

Job description

Creates cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate data and cyber security risks. Designs and develops acceptance criteria for cybersecurity architecture.

  • Perform infrastructure penetration testing to discover and exploit vulnerabilities to test the effectiveness of the organization’s security posture.
  • Perform web application penetration testing to identify and exploit OWASP Top 10 web application vulnerabilities.
  • Leverage threat intelligence to emulate known threat actors’ tactics, techniques, and procedures.
  • Partner with various cybersecurity teams to improve automation and detection of threat actors.
  • Engage with technical and non-technical audiences to articulate both techniques and results.

Requirements

  • Bachelor’s Degree in Computer Science or a related field or equivalent experience.
  • 5-10 years of experience in systems security with a minimum of 2+ years in information security, penetration testing, or ethical hacking.

Other Job Specific Skills

  • Must possess demonstrated experience planning and conducting penetration tests against networks and web applications.
  • Demonstrated experience conducting vulnerability assessments and penetration tests.
  • Expertise with tools such as Bloodhound, Burp Suite, Cobalt Strike, Metasploit, and Mimikatz.
  • Hands-on experience with penetration testing tools and frameworks.
  • Portfolio of security assessments or CTF achievements (preferred).
  • Experience with network scanning, enumeration, and exploiting vulnerabilities.
  • Proficiency in Windows, Linux, and macOS environments.
  • Understanding of system hardening techniques and common misconfigurations.
  • Knowledge of programming languages like Python, Ruby, or JavaScript for creating custom scripts and exploits.
  • Familiarity with bash, PowerShell, or other scripting languages for automation.
  • Understanding of web technologies, including HTML, JavaScript, and SQL.

Preferred Skills

  • Experience in identifying and exploiting vulnerabilities in web applications, networks, and systems.
  • Familiarity with CVSS (Common Vulnerability Scoring System) and understanding how to prioritize vulnerabilities based on risk.
  • Ability to analyze and critique code for security vulnerabilities.
  • Familiarity with common vulnerabilities such as SQL injection, XSS (Cross-Site Scripting), CSRF (Cross-Site Request Forgery), and buffer overflows.
  • Strong understanding of network protocols, architecture, and components (e.g., TCP/IP, DNS, HTTP, VPNs, firewalls, routers, switches).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:21 min

Projecting external HTML content using default and named slots

Rowdy Rabouw Rowdy Rabouw · World Congress 2022

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

3:30 min

Falling in love with Ruby and creating Basecamp

David Heinemeier Hansson David Heinemeier Hansson +1 · Coffee With Developers

Videos

See all

Related articles

See all