> Markdown version of [/jobs/ext/2571557-penetration-tester-offensive-security-consultant](https://www.wearedevelopers.com/jobs/ext/2571557-penetration-tester-offensive-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester / Offensive Security Consultant - **Company:** Synercomm, Inc. - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, User Authentication, Microsoft Azure, Burp Suite, C Sharp (Programming Language), Software as a Service, Cloud Computing, Computer Networks, Linux, Mobile Application Software, Python (Programming Language), Nmap, Windows PowerShell, Reverse Engineering, Software Engineering, TypeScript, Web Applications, Scripting, Cloud Platform System, Software Security, Metasploit, Free and Open-Source Software, Application Client - **Published:** August 25, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2dea6a33ef4300c1 ## About the Role Join a growing offensive security practice where curiosity, technical depth, and the ability to think like an attacker matter. You will perform hands-on penetration testing, work directly with clients, and help shape the next generation of our testing capabilities, tooling, automation, and AI-assisted workflows., * Hands-on experience with penetration testing, offensive security, application security, security research, systems administration, software development, artificial intelligence and closely related technical disciplines. * Strong understanding of common operating systems, networking concepts, authentication technologies, and security controls. * Working knowledge of modern penetration testing techniques and common vulnerability classes. * Ability to work remotely, independently, manage time effectively, and collaborate closely with teammates. * Strong written and verbal communication skills, including the ability to explain technical issues to both technical and non-technical audiences. * A consulting mindset, professional judgment, and a commitment to performing security testing responsibly and ethically. * Curiosity and a willingness to learn. We value people who enjoy figuring out how things work and who are motivated to keep improving their craft. * Willingness to travel when an engagement benefits from on-site testing or client interaction. Additional travel for company events and meetings (avg. 2-3 times per year)., * OSCP or OSCE certification and 4+ years of penetration testing experience. * Experience using frontier AI models, especially code and tool development for offensive security. * Experience testing Active Directory, Entra ID, Windows, Linux, web applications, APIs, cloud environments, or mobile applications. * Experience with tools and frameworks such as Burp Suite, CobaltStrike, Nmap, BloodHound, Impacket, NetExec, Metasploit, and other modern offensive security tooling. * Software development or scripting experience with Python, PowerShell, C#, JavaScript/TypeScript, Go, or other languages used to build or adapt technical tools. * Experience developing exploits, modifying proof-of-concept code, performing reverse engineering, or bypassing security controls. * Experience with AWS, Microsoft Azure, Microsoft 365, or other cloud and SaaS environments. * Interest or experience using AI to support security research, testing workflows, automation, analysis, or development of new offensive security capabilities. * Security research, CTF participation, lab environments, open-source contributions, technical writing, or other evidence of hands-on curiosity outside of assigned work. * Practical technical ability and experience are more important to us than any specific certification. ## Description * Perform infrastructure, network, web application, API, and other penetration testing engagements for clients. * Assess Microsoft Active Directory, Entra ID, and related identity and authentication environments. * Identify attack paths, validate security controls, and demonstrate the real-world impact of vulnerabilities when appropriate. * Perform application security reviews, including testing of web applications, services, APIs, mobile applications, and other client software as needed. * Participate in social engineering, wireless, cloud, and other specialized security assessments based on experience and project needs. * Develop clear, professional reports that explain technical findings, business risk, and practical remediation guidance. * Communicate directly with clients before, during, and after engagements, representing SynerComm professionally and collaboratively. * Research new attack techniques, technologies, tools, and defensive controls to continuously improve our testing methodologies. * Build, modify, or automate tools and workflows when established tools are not enough for the job. * Collaborate with teammates to improve our services, methodologies, internal tooling, and overall client experience. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)