Sr. Penetration Tester
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+20 more
Job description
Be an Early Applicant In-Office or Remote Hiring Remotely in United States 120-160 Hourly Mid level In-Office or Remote Hiring Remotely in United States 120-160 Hourly Mid level Conduct web, mobile, API, network, and social engineering penetration tests; identify vulnerabilities, develop technical reports, recommend mitigations, and present findings to clients. Ensure assessments align with GDPR, PCI-DSS, SOC 2, and other standards while tracking emerging threats. The role is remote and contract-based, with cloud security, certifications, mobile testing, API security, and scripting experience preferred. The summary above was generated by AI
Velero is a cybersecurity and compliance consulting firm helping clients navigate complex regulatory requirements through expert-led assessments, advisory services, and practical security execution. Working across the computer and network security space, we partner with organizations to strengthen their security posture with clear, actionable guidance grounded in real-world risk.
In this role, you will help clients uncover vulnerabilities across a range of environments and contribute to security assessments that support both technical resilience and regulatory readiness. This is an opportunity for a penetration tester who enjoys tackling varied engagements, communicating findings clearly, and translating complex security issues into practical next steps for internal teams and clients. Responsibilities
- Conduct penetration tests on web applications, mobile applications, and APIs to identify vulnerabilities and potential exploits.
- Perform network penetration testing, including internal and external network assessments, to ensure comprehensive coverage of security weaknesses.
- Implement social engineering techniques such as phishing campaigns to simulate real-world attacks and identify human-related security risks.
- Prepare detailed technical reports and provide actionable recommendations based on the results of penetration tests.
- Collaborate with internal teams and external clients to discuss findings, mitigation strategies, and security best practices.
- Ensure compliance with relevant security standards and regulations, including GDPR, PCI-DSS, SOC 2, and others.
- Stay up to date on emerging threats, vulnerabilities, and security best practices., Performs application, network, wireless, and enclave penetration testing for a DoD client. Identifies cybersecurity vulnerabilities, develops mitigation strategies, coordinates testing with system owners, and prepares assessment reports and recommendations. The role requires extensive vulnerability assessment experience, knowledge of Windows, Linux, networking, OWASP, PCI DSS, scripting, and penetration testing tools. A DoD Secret clearance and eligibility for IT-I Critical Sensitive or Tier 5 clearance are required. Top Skills: BashBurp SuiteCanvasIisJavaKismetLinuxMetasploitNessusNmapOwaspPci DssPerlPythonRubyTcp/IpWindows ServerWireless Lan Security CACI International Inc
Requirements
- Proven experience (3+ years) in penetration testing across web apps, mobile apps, APIs, and network environments.
- Expertise in internal and external network penetration testing.
- Knowledge of common security vulnerabilities and attack vectors, such as those listed in OWASP Top 10 and MITRE ATT&CK.
- Familiarity with industry-standard tools like Burp Suite, Nmap, Metasploit, Wireshark, Nessus, and others.
- Experience with cloud environments (AWS, Azure, Google Cloud) is a plus.
- Strong understanding of GDPR, PCI-DSS, SOC 2, and other regulatory frameworks.
- Excellent verbal and written communication skills, with the ability to present findings to technical and non-technical audiences.
Preferred Skills & Certifications:
- Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), GIAC Penetration Tester (GPEN), or similar certifications.
- Experience with mobile security frameworks and tools such as OWASP Mobile Security Testing Guide (MSTG).
- Experience in API security testing, including OAuth and other common API security models.
- Proficiency in one or more programming/scripting languages (Python, Bash, JavaScript, etc.).
Benefits & conditions
This position offers a flexible, remote contract opportunity for penetration testers looking to work on exciting security challenges in a nearshore environment. If you are a skilled security professional passionate about identifying vulnerabilities and strengthening security, we’d welcome your application.Why Join Us?
- Competitive compensation of 120-160 USD per hour.
- Flexibility of remote work with a nearshore focus., Remote 2 Locations 90K-130K Annually Mid level 90K-130K Annually Mid level Information Technology * Cybersecurity Conduct infrastructure penetration tests, cloud security assessments, Active Directory reviews, red team operations, adversary simulations, and purple team exercises across on-premises, hybrid, and cloud environments. Identify and validate vulnerabilities, execute attack scenarios, prepare technical reports, present findings, advise clients on remediation, and improve offensive security methodologies, tooling, documentation, and service offerings. The role also requires managing engagement timelines, collaborating with consultants, and maintaining expertise in emerging attack techniques. Top Skills: Active DirectoryAWSCi/Cd PipelinesCloud-Native TechnologiesEnterprise NetworkingGoogle Cloud PlatformKubernetesLinuxAzureMicrosoft Entra IdVirtualization PlatformsWindowsWireless Networks Amyx, Inc., 21 Days Ago In-Office or Remote 90K-190K Annually Senior level 90K-190K Annually Senior level Information Technology * Consulting * Defense Leads penetration-testing engagements across networks, applications, cloud, identity systems, and exposed assets. Owns scoping, rules of engagement, planning, execution, evidence validation, vulnerability prioritization, reporting, customer briefings, remediation clarification, and quality review. Mentors junior testers while conducting hands-on testing involving privilege escalation, lateral movement, pivoting, and controlled exploitation. Supports federal CDM cybersecurity assessments and escalates safety, scope, and material findings. Top Skills: Active DirectoryAd CsAWSAzureBloodhoundBurp Suite ProCertifyCertipyCisa KevCvssImpacketKubernetesLinuxMetasploitNessusNetexecNmapOwasp ZapPowerviewTcpdumpTenableWindowsWireshark
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Dev Digest 134 - Where pixels sing?
The 8 Best Code Testing Tools
The Overflow: Security and Privacy