> Markdown version of [/jobs/ext/2179903-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2179903-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** DUNHILL PROFESSIONAL SEARCH - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $90,000.0 - $109,000.0 - **Contract:** Permanent contract - **Skills:** HTML, JavaScript (Programming Language), Microsoft Windows, Apple Mac Systems, Software System Penetration Testing, Bash Shell, Burp Suite, Cyber Security, Cross-Site Request Forgery, Linux, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Python (Programming Language), Network Protocols, Open Web Application Security, Windows PowerShell, Ruby, SQL Injection, SQL Databases, TCP/IP, Web Applications, Network Routers, Scripting, Firewalls (Computer Science), Cross-Site Scripting (XSS), Information Technology, Metasploit, Web Technologies, Vulnerability Analysis, Programming Languages - **Published:** August 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9109270/penetration-tester ## About the Role * Bachelor's Degree in Computer Science or a related field or equivalent experience. * 5-10 years of experience in systems security with a minimum of 2+ years in information security, penetration testing, or ethical hacking. Other Job Specific Skills * Must possess demonstrated experience planning and conducting penetration tests against networks and web applications. * Demonstrated experience conducting vulnerability assessments and penetration tests. * Expertise with tools such as Bloodhound, Burp Suite, Cobalt Strike, Metasploit, and Mimikatz. * Hands-on experience with penetration testing tools and frameworks. * Portfolio of security assessments or CTF achievements (preferred). * Experience with network scanning, enumeration, and exploiting vulnerabilities. * Proficiency in Windows, Linux, and macOS environments. * Understanding of system hardening techniques and common misconfigurations. * Knowledge of programming languages like Python, Ruby, or JavaScript for creating custom scripts and exploits. * Familiarity with bash, PowerShell, or other scripting languages for automation. * Understanding of web technologies, including HTML, JavaScript, and SQL. Preferred Skills * Experience in identifying and exploiting vulnerabilities in web applications, networks, and systems. * Familiarity with CVSS (Common Vulnerability Scoring System) and understanding how to prioritize vulnerabilities based on risk. * Ability to analyze and critique code for security vulnerabilities. * Familiarity with common vulnerabilities such as SQL injection, XSS (Cross-Site Scripting), CSRF (Cross-Site Request Forgery), and buffer overflows. * Strong understanding of network protocols, architecture, and components (e.g., TCP/IP, DNS, HTTP, VPNs, firewalls, routers, switches). ## Description Creates cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate data and cyber security risks. Designs and develops acceptance criteria for cybersecurity architecture. * Perform infrastructure penetration testing to discover and exploit vulnerabilities to test the effectiveness of the organization's security posture. * Perform web application penetration testing to identify and exploit OWASP Top 10 web application vulnerabilities. * Leverage threat intelligence to emulate known threat actors' tactics, techniques, and procedures. * Partner with various cybersecurity teams to improve automation and detection of threat actors. * Engage with technical and non-technical audiences to articulate both techniques and results. ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [Hack-Proof The Node.js runtime: The Mechanics and Defense of Path Traversal Attacks](https://www.wearedevelopers.com/videos/716-hack-proof-the-node-js-runtime-the-mechanics-and-defense-of-path-traversal-attacks) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [11 Best Practices For PHP Security](https://www.wearedevelopers.com/magazine/90-11-best-practices-for-php-security) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)