> Markdown version of [/jobs/ext/231902-senior-penetration-tester-us](https://www.wearedevelopers.com/jobs/ext/231902-senior-penetration-tester-us). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Penetration Tester (US) - **Company:** BreachLock, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Private Networks, Active Directory, Application Programming Interfaces (APIs), Business Logic, Software System Penetration Testing, User Authentication, Bash Shell, Burp Suite, Python (Programming Language), NT LAN Manager, Open Web Application Security, Windows PowerShell, Session Management, Security Information and Event Management, Web Applications, Mitre Att&ck, GWAPT, Api Management - **Published:** May 26, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2d9384bd6a706bdd ## About the Role Do you have experience in Writing skills?, * 3-5 years of professional penetration testing experience in a delivery or consulting context * Strong web application and API testing fundamentals - Burp Suite proficiency, OWASP Top 10 and beyond, authentication and session management testing * Solid internal network assessment skills - AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, assumed breach methodology * Proficiency in scripting and automation (Python, PowerShell, Bash) * Strong written communication - capable of writing clear, accurate, well-scoped findings independently * Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus * US-based and eligible to work without sponsorship Preferred * Experience with C2 frameworks (Cobalt Strike, Havoc, Sliver, or similar) * Active involvement in cybersecurity communities, research, or bug bounty programs * Certifications such as OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent practical credentials * Experience with SIEM platforms or EDR tools from an adversarial perspective ## Description As a penetration tester on BreachLock's US Strategic delivery team, you'll execute manual, methodology-driven engagements across web applications, APIs, and internal networks - including assumed breach simulations - for enterprise clients. You'll work directly with delivery leadership, contribute to internal tooling and quality systems, and help raise the bar for the team around you., * Execute web application, API and mobile penetration tests with a focus on manual testing beyond automated scanning - business logic, authentication abuse, authorization flaws, and injection chains * Conduct internal network assessments, external network assessments and assumed breach engagements, including Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation * Leverage frameworks including MITRE ATT&CK, PTES, and OWASP to structure assessments and findings * Develop and contribute to internal tooling - automation scripts, reporting utilities, and workflow improvements using Python, Bash, or similar * Participate in QA review cycles, providing structured feedback on findings, CVSS scoring accuracy, and report quality * Mentor junior testers through technical guidance and finding review * Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)