> Markdown version of [/jobs/ext/2592928-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2592928-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** LANDGRAF CORP - **Location:** United States (Remote available) - **Salary:** $40,000.0 - $80,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9fb643c1b0412137 ## About the Role * OSCP required (or actively pursuing); CEH/GPEN a plus * Demonstrated hands-on experience in offensive security or vulnerability assessment * Comfort working directly with small-business clients, not just technical teams * Entrepreneurial mindset - this is a startup, not an established firm ## Description Landgraf Defense is an early-stage cybersecurity firm offering vulnerability assessments, penetration testing, and fractional-CISO advisory to small and mid-size businesses. We're looking for a technically certified security professional to join as a founding partner - not a standard hire - and build the delivery side of the business alongside a business/sales-focused co-founder. This is a ground-floor opportunity: you'll shape service offerings, pricing, and technical methodology from day one, with a direct path to equity ownership as the business scales. What You'll Do * Conduct vulnerability assessments and penetration tests for SMB clients * Design and deliver findings reports and remediation guidance * Advise clients on security posture as a fractional resource * Help refine service packaging and technical credibility in client-facing meetings ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Lessons learned from observing a billion API requests](https://www.wearedevelopers.com/videos/1574-lessons-learned-from-observing-a-billion-api-requests) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)