Penetration Tester / Offensive Security Consultant

Synercomm, Inc.
United States
9 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Microsoft Windows Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Software System Penetration Testing User Authentication Microsoft Azure Burp Suite C Sharp (Programming Language) Software as a Service
+17 more
Cloud Computing Computer Networks Linux Mobile Application Software Python (Programming Language) Nmap Windows PowerShell Reverse Engineering Software Engineering TypeScript Web Applications Scripting Cloud Platform System Software Security Metasploit Free and Open-Source Software Application Client

Job description

  • Perform infrastructure, network, web application, API, and other penetration testing engagements for clients.
  • Assess Microsoft Active Directory, Entra ID, and related identity and authentication environments.
  • Identify attack paths, validate security controls, and demonstrate the real-world impact of vulnerabilities when appropriate.
  • Perform application security reviews, including testing of web applications, services, APIs, mobile applications, and other client software as needed.
  • Participate in social engineering, wireless, cloud, and other specialized security assessments based on experience and project needs.
  • Develop clear, professional reports that explain technical findings, business risk, and practical remediation guidance.
  • Communicate directly with clients before, during, and after engagements, representing SynerComm professionally and collaboratively.
  • Research new attack techniques, technologies, tools, and defensive controls to continuously improve our testing methodologies.
  • Build, modify, or automate tools and workflows when established tools are not enough for the job.
  • Collaborate with teammates to improve our services, methodologies, internal tooling, and overall client experience.

Requirements

Join a growing offensive security practice where curiosity, technical depth, and the ability to think like an attacker matter. You will perform hands-on penetration testing, work directly with clients, and help shape the next generation of our testing capabilities, tooling, automation, and AI-assisted workflows., * Hands-on experience with penetration testing, offensive security, application security, security research, systems administration, software development, artificial intelligence and closely related technical disciplines.

  • Strong understanding of common operating systems, networking concepts, authentication technologies, and security controls.
  • Working knowledge of modern penetration testing techniques and common vulnerability classes.
  • Ability to work remotely, independently, manage time effectively, and collaborate closely with teammates.
  • Strong written and verbal communication skills, including the ability to explain technical issues to both technical and non-technical audiences.
  • A consulting mindset, professional judgment, and a commitment to performing security testing responsibly and ethically.
  • Curiosity and a willingness to learn. We value people who enjoy figuring out how things work and who are motivated to keep improving their craft.
  • Willingness to travel when an engagement benefits from on-site testing or client interaction. Additional travel for company events and meetings (avg. 2-3 times per year)., * OSCP or OSCE certification and 4+ years of penetration testing experience.
  • Experience using frontier AI models, especially code and tool development for offensive security.
  • Experience testing Active Directory, Entra ID, Windows, Linux, web applications, APIs, cloud environments, or mobile applications.
  • Experience with tools and frameworks such as Burp Suite, CobaltStrike, Nmap, BloodHound, Impacket, NetExec, Metasploit, and other modern offensive security tooling.
  • Software development or scripting experience with Python, PowerShell, C#, JavaScript/TypeScript, Go, or other languages used to build or adapt technical tools.
  • Experience developing exploits, modifying proof-of-concept code, performing reverse engineering, or bypassing security controls.
  • Experience with AWS, Microsoft Azure, Microsoft 365, or other cloud and SaaS environments.
  • Interest or experience using AI to support security research, testing workflows, automation, analysis, or development of new offensive security capabilities.
  • Security research, CTF participation, lab environments, open-source contributions, technical writing, or other evidence of hands-on curiosity outside of assigned work.
  • Practical technical ability and experience are more important to us than any specific certification.

Benefits & conditions

  • Work with an experienced team of security consultants performing real, hands-on testing for a wide variety of clients and environments. Our team blogs under the name #_shellntel (https://blog.shellntel.com).
  • Grow beyond a single testing specialty and develop deeper expertise across infrastructure, applications, identity, cloud, social engineering, research, and other areas of offensive security.
  • Help influence how our penetration testing practice evolves as we continue to invest in growth, new clients, new capabilities, and new team members.
  • Experiment with new technologies, automation, development, and AI-assisted approaches that can make our testing more effective and create new value for clients. SynerComm also resells all the top cybersecurity controls giving our pentesters access to experiment with all the latest technologies.
  • Take increasing ownership as your skills grow, including opportunities to lead complex engagements, mentor teammates, improve methodologies, and help develop new services.

About the company

SynerComm, Inc. is seeking a full-time, remote penetration tester to join our Services team. Our consultants perform hands-on security testing for clients across networks, systems, applications, identity environments, and other areas where real-world attack techniques can help organizations better understand risk.

This role is designed for someone who enjoys learning how technologies work, challenging assumptions, solving difficult technical problems, and communicating clearly with clients. We are interested in experienced penetration testers as well as emerging offensive security professionals who have strong technical fundamentals, practical experience, and the drive to continue growing., SynerComm provides information security consulting and professional services to clients through our #_shellntel pentesting team. Our team is focused on delivering practical, high-quality security assessments and helping clients understand and reduce real-world risk. We are continuing to invest in the growth of our services practice and are looking for talented people who want to help us build what comes next.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all