> Markdown version of [/jobs/ext/2957788-security-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2957788-security-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Penetration Tester - **Company:** Xerox - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Burp Suite, Computer Programming, Imaging Technology, Python (Programming Language), Kali Linux, Nmap, Open Web Application Security, PCI Data Security Standards, Windows PowerShell, Red Team (Cyber Security), Secure Coding, Security Software, Web Applications, Scripting, Cloud Platform System, Bug Reporting, Metasploit, Nessus - **Published:** September 17, 2026 - **Apply:** https://xerox.avature.net/en_US/careers/Login?jobId=52248 ## About the Role * Approximately 3 years of professional experience in penetration testing, offensive security, or a closely related role. * Must be based in the United States and authorized to work in the U.S. without sponsorship. * Solid understanding of common vulnerability classes (OWASP Top 10, network-layer attacks, privilege escalation, etc.). * Hands-on experience with penetration testing tools and frameworks (Burp Suite, Metasploit, Nmap, Kali Linux, etc.). * Working knowledge of scripting/programming (Python, Bash, or PowerShell) for tooling and automation. * Strong written communication skills for producing clear, actionable technical reports. * Ability to work independently in a remote environment while collaborating across distributed teams. Preferred Qualifications * Industry certifications such as OSCP, CEH, or GPEN (preferred, not required). * Experience testing cloud environments (AWS, Azure, or GCP). * Familiarity with secure code review or application security testing. * Prior experience in a regulated industry (e.g., government, healthcare, finance, or print/imaging technology). ## Description XCS (Xerox) is seeking a Penetration Tester with approximately 3 years of hands-on experience to join our Offensive Security team. In this role, you will identify, exploit, and help remediate security vulnerabilities across our applications, networks, and infrastructure through simulated attacks, contributing directly to the security posture of our products and enterprise environment., * Plan and execute penetration tests against web applications, networks, APIs, and cloud environments to identify exploitable vulnerabilities. * Perform manual and automated security testing using industry-standard tools (e.g., Burp Suite, Metasploit, Nmap, Nessus, Cobalt Strike). * Document findings clearly in professional reports, including risk ratings, reproduction steps, and remediation recommendations. * Collaborate with engineering and IT teams to validate fixes and re-test remediated issues. * Stay current on emerging threats, attack techniques, and vulnerability disclosures relevant to Xerox's technology stack. * Support red team exercises, social engineering assessments, or physical security tests as needed. * Contribute to internal tooling, scripts, or playbooks that improve testing efficiency and coverage. * Assist with compliance-driven testing (e.g., PCI-DSS, SOC 2) as required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [11 Best Practices For PHP Security](https://www.wearedevelopers.com/magazine/90-11-best-practices-for-php-security) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)