Penetration Tester

Information Management Resources, Inc.
New York, NY, United States
5 days ago
Apply on www.thejobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Shift work

Tech stack

Software System Penetration Testing Burp Suite CompTIA Security+ Cyber Security Kali Linux Network Security Nmap Open Web Application Security Comptia Pentest+ CE Web Application Security Wireshark Web Applications
+6 more
Firewalls (Computer Science) Information Technology Metasploit Nessus CIS Benchmarks Vulnerability Analysis

Job description

SUMMARY: IMRI is seeking a part-time Senior Penetration Tester to support cybersecurity assessment and penetration testing activities focused on enterprise penetration testing. This role provides hands-on technical testing expertise to identify exploitable weaknesses, validate attack paths, assess risk, use manual and automated penetration testing approaches, and deliver practical remediation guidance while maintaining compliance with approved rules of engagement., LOCATION/SCHEDULE: Hybrid or onsite as required supporting Nassau County, NY. Majority of work will be performed during standard business hours Monday-Friday, 8:00 AM-5:00 PM EST, with occasional nights, weekends, or approved maintenance-window support during OT/ICS discovery, rules-of-engagement coordination, testing execution, validation, reporting, and stakeholder briefings., * Perform hands-on internal and external penetration testing, web application security testing, wireless assessment, firewall review, vulnerability validation, segmentation analysis, and controlled exploit testing across approved enterprise, government, and operational environments.

  • Support approximately 900 hours of annual senior penetration testing activities for County IT, District Attorney, Police Department, web application, wireless, firewall, infrastructure, and enterprise security validation activities.
  • Coordinate closely with government client IT, legal or investigative stakeholders, authorized liaisons, system owners, and other stakeholders to minimize disruption and protect mission-critical operations.
  • Use automated penetration testing and attack-path validation tools, including Horizon3.ai where applicable, in coordination with approved rules of engagement, testing windows, credential handling requirements, and safety constraints.
  • Analyze findings using risk-based methods aligned to NIST CSF, NIST SP 800-53, NIST SP 800-115, CIS Controls, CVE/CVSS, OWASP, PTES, and applicable CJIS considerations.
  • Develop detailed technical findings, evidence, attack-path narratives, operational impact analysis, prioritized remediation recommendations, and executive-ready summaries.
  • Participate in client briefings, remediation planning, retesting, lessons learned, and knowledge transfer activities to support long-term operational resilience.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent professional experience.
  • 5+ years of cybersecurity assessment, penetration testing, vulnerability assessment, network security, or security engineering experience, including senior-level enterprise penetration testing experience.
  • Experience with penetration testing methodologies, vulnerability validation, attack-path analysis, firewall and network-device review, wireless assessment, automated penetration testing tools including Horizon3.ai, and secure reporting practices.
  • Strong written communication, technical reporting, stakeholder coordination, and executive briefing skills., * Experience with tools such as Horizon3.ai, Tenable/Nessus, Nmap, Wireshark, Burp Suite, Metasploit, Kali Linux, firewall review tools, and vulnerability validation utilities.
  • Relevant certifications such as GPEN, CISSP, CISM, CRISC, CEH, PenTest+, Security+, Network+, CCNA, or equivalent cybersecurity credentials.
  • Experience preparing executive and technical reports that include attack-path narratives, risk ratings, remediation sequencing, and retesting criteria.

Benefits & conditions

At IMRI, we recognize the integral part our employees play in our ongoing success. To support this, we offer a comprehensive benefits package, tailored to meet the individual needs of our employees. We are committed to promoting their overall well-being and equipping them with the necessary tools to flourish in their careers. We welcome you to be a part of our ongoing mission as we continue to navigate the digital landscape, committed to empowering organizations with our innovative solutions., IMRI offers top-tier benefits that include: medical coverage through nationally recognized carriers, ancillary coverages, paid vacation and sick leave in compliance with all state and local laws, 401(k) with company match, company paid life insurance and LTD, and several additional voluntary coverages.

Pay will be commensurate with the experience, skills, and qualifications that the candidate brings to the position.

About the company

Join our award-winning team at Information Management Resources, Inc. (IMRI), a small business leader in the technology industry known for our commitment to innovation, excellence, and authenticity. Founded in 1992, IMRI has been at the forefront of delivering advanced cybersecurity and IT solutions, safeguarding organizations against evolving threats. We have built a reputation for our expertise in Cybersecurity, Digital Transformation, Strategic Business Consulting, and Staff Augmentation. Guided by our core values of innovation, excellence, and a solution-driven mindset, we have served a diverse portfolio of customers that includes federal agencies, state and local governments, and Fortune 1000 companies.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thejobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

3:19 min

Setting up a vulnerable test application and monitoring environment

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2024

7:01 min

Initial reconnaissance and port scanning execution

Antonio De Mello +1 · LIVE

6:24 min

Common information security tools and terminologies

Antonio De Mello +1 · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

1:48 min

Analyzing network packets with database protocol tools

Daniël van Eeden Daniël van Eeden · World Congress 2026 Europe

Videos

See all

Related articles

See all