Penetration Tester (PenTester)

BW CYBER, LLC
United States
3 months ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$115,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Perl (Programming Language) Python (Programming Language) Wireless Security Windows PowerShell Phishing Ruby SAP NetWeaver Business Warehouse Web Applications Scripting Information Technology Metasploit
+3 more
Nessus Qualys Vulnerability Analysis

Job description

BW Cyber, LLC is a full-service cybersecurity consulting firm with a focus on assisting clientele in the financial and wealth management industries, among others. The firm is veteran-owned, with many of our staff having served in various branches of the United States’ military. We are seeking an experienced Penetration Tester (red teaming, offensive cybersecurity) to join our ranks in a full-time and fully remote US-based role. The right candidate will have five years of prior relevant experience, and will be well-organized, comfortable communicating with clients and collaborating, mission-oriented, eager to learn, and ready to make an impact helping BW Cyber protect the cybersecurity interests of its clients. Further details on company contact information, requirements, and expectations of the role can be found below. Note: For any transitioning service members, this role is also open for Skillbridge Internship consideration, please review below., * Perform technical security assessments of client environments which include (non-exclusive): Infrastructure Penetration Tests, Vulnerability Assessments, Web Application Tests, Wireless Security Tests, Social Engineering Campaigns (phishing, spearphishing, and pretexting), Public Cloud Security Reviews

  • Develop rules of engagement, and configure, tune, and operate industry standard assessment tools
  • Coordinate, schedule, and support security testing requests
  • Evaluate findings to determine applicability, saturation, and potential impact
  • Analyze results and produce reports for clients: Detailed technical reports for IT staff, High-level summary presentations for executives
  • Advise client stakeholders of findings and provide remediation guidance
  • As appropriate, monitor remediation efforts of findings and communicate progress to stakeholders
  • As appropriate, work with client stakeholders to develop Plan of Action & Milestones (POA&M) tracker to ensure identified weaknesses are addressed in a timely and cost-effective manner
  • As needed, assist in cyber incident response for clients

Requirements

Do you have experience in Penetration testing tools?, Do you have a Associate’s degree?, * Expertise creating exploits for vulnerabilities or demonstrated expertise using a scripting language such as PowerShell, Python, Ruby, or Perl for penetration testing

  • Expert in common vulnerability scanners (e.g., Nessus, OpenVAS, Qualys)
  • Expert in common penetration testing tools (e.g., Metasploit, Burp, ZAP)

Preferred Requirements

  • Though not mandatory, Associate’s Degree or higher in cybersecurity/computer science a plus
  • A minimum of 5 years of experience in penetration testing
  • One of the following active certifications preferred (BW Cyber will consider other certifications): Exploit Researcher and Advanced Penetration Tester (GXPN), Offensive Security Certified Expert (OSCE), Offensive Security Certified Professional (OSCP), Offensive Security Exploitation Expert (OSEE), GIAC Penetration Tester (GPEN), Certified Ethical Hacker (CEH), or 1+ years’ experience responding to Advanced Persistent Threat (APT) type incidents
  • This opportunity does not require the utilization of a U.S. government security clearance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

3:30 min

Falling in love with Ruby and creating Basecamp

David Heinemeier Hansson David Heinemeier Hansson +1 · Coffee With Developers

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

1:51 min

Corporate influence and governance in open source communities

Chris Heilmann +2 · LIVE

Videos

See all

Related articles

See all