> Markdown version of [/jobs/ext/3550544-penetration-tester](https://www.wearedevelopers.com/jobs/ext/3550544-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** Information Management Resources, Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Burp Suite, CompTIA Security+, Cyber Security, Kali Linux, Network Security, Nmap, Open Web Application Security, Comptia Pentest+ CE, Web Application Security, Wireshark, Web Applications, Firewalls (Computer Science), Information Technology, Metasploit, Nessus, CIS Benchmarks, Vulnerability Analysis - **Published:** September 30, 2026 - **Apply:** https://www.thejobnetwork.com/job/8f03c30c-a653-49b0-bf2b-e1b6d21310e8/parttime-sr-penetration-tester ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent professional experience. * 5+ years of cybersecurity assessment, penetration testing, vulnerability assessment, network security, or security engineering experience, including senior-level enterprise penetration testing experience. * Experience with penetration testing methodologies, vulnerability validation, attack-path analysis, firewall and network-device review, wireless assessment, automated penetration testing tools including Horizon3.ai, and secure reporting practices. * Strong written communication, technical reporting, stakeholder coordination, and executive briefing skills., * Experience with tools such as Horizon3.ai, Tenable/Nessus, Nmap, Wireshark, Burp Suite, Metasploit, Kali Linux, firewall review tools, and vulnerability validation utilities. * Relevant certifications such as GPEN, CISSP, CISM, CRISC, CEH, PenTest+, Security+, Network+, CCNA, or equivalent cybersecurity credentials. * Experience preparing executive and technical reports that include attack-path narratives, risk ratings, remediation sequencing, and retesting criteria. ## Description SUMMARY: IMRI is seeking a part-time Senior Penetration Tester to support cybersecurity assessment and penetration testing activities focused on enterprise penetration testing. This role provides hands-on technical testing expertise to identify exploitable weaknesses, validate attack paths, assess risk, use manual and automated penetration testing approaches, and deliver practical remediation guidance while maintaining compliance with approved rules of engagement., LOCATION/SCHEDULE: Hybrid or onsite as required supporting Nassau County, NY. Majority of work will be performed during standard business hours Monday-Friday, 8:00 AM-5:00 PM EST, with occasional nights, weekends, or approved maintenance-window support during OT/ICS discovery, rules-of-engagement coordination, testing execution, validation, reporting, and stakeholder briefings., * Perform hands-on internal and external penetration testing, web application security testing, wireless assessment, firewall review, vulnerability validation, segmentation analysis, and controlled exploit testing across approved enterprise, government, and operational environments. * Support approximately 900 hours of annual senior penetration testing activities for County IT, District Attorney, Police Department, web application, wireless, firewall, infrastructure, and enterprise security validation activities. * Coordinate closely with government client IT, legal or investigative stakeholders, authorized liaisons, system owners, and other stakeholders to minimize disruption and protect mission-critical operations. * Use automated penetration testing and attack-path validation tools, including Horizon3.ai where applicable, in coordination with approved rules of engagement, testing windows, credential handling requirements, and safety constraints. * Analyze findings using risk-based methods aligned to NIST CSF, NIST SP 800-53, NIST SP 800-115, CIS Controls, CVE/CVSS, OWASP, PTES, and applicable CJIS considerations. * Develop detailed technical findings, evidence, attack-path narratives, operational impact analysis, prioritized remediation recommendations, and executive-ready summaries. * Participate in client briefings, remediation planning, retesting, lessons learned, and knowledge transfer activities to support long-term operational resilience. ## Related Videos - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [11 Best Practices For PHP Security](https://www.wearedevelopers.com/magazine/90-11-best-practices-for-php-security)