Lead Penetration Tester

Xtreme Inc
Traverse City, MI, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Application Programming Interfaces (APIs) Software System Penetration Testing Burp Suite Cloud Computing Cloud Computing Security Cyber Security Kali Linux Nmap Open Web Application Security PCI Data Security Standards
+7 more
Red Team (Cyber Security) Web Applications Cloud Platform System Information Technology Metasploit Nessus Wireless Technologies

Job description

Xtreme Solutions will execute the assessment over a five-week period utilizing a team of certified cybersecurity professionals specializing in penetration testing, Microsoft 365 security, Active Directory security, cloud security, and cybersecurity reporting. Activities begin with project kickoff and rules of engagement development, followed by concurrent external, internal, and Microsoft 365 security assessments. Findings are validated through peer review and quality assurance processes before being compiled into comprehensive technical and executive-level reports. The engagement concludes with an executive briefing and remediation roadmap presentation. Optional retesting services may be performed following remediation activities to validate corrective actions and confirm risk reduction., The Lead Penetration Tester serves as the technical authority for all penetration testing activities and is responsible for planning, executing, and reporting on security assessments of networks, applications, cloud environments, wireless systems, and enterprise infrastructure. The Lead Penetration Tester provides overall quality assurance, validates findings, and briefs executive stakeholders on risk and remediation strategies., * Lead external and internal penetration testing engagements.

  • Conduct network, web application, API, cloud, and wireless assessments.
  • Develop attack scenarios based on real-world adversary tactics.
  • Perform manual exploitation and validation of vulnerabilities.
  • Lead red team exercises and adversary emulation operations.
  • Document findings with technical evidence and remediation recommendations.
  • Present assessment results to technical and executive audiences.
  • Ensure testing activities align with NIST, OWASP, PCI-DSS, and FedRAMP requirements.
  • Mentor junior penetration testers and review deliverables.

Requirements

Do you have experience in Vuls?, Do you have a Bachelor’s degree?, * Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field.

  • Minimum 8 years of cybersecurity experience.
  • Minimum 5 years of penetration testing experience.
  • One or more of the following certifications:
  • OSCP
  • OSCE
  • GXPN
  • GPEN
  • CEH
  • CPTE
  • Experience with:
  • Burp Suite
  • Metasploit
  • Kali Linux
  • Nmap
  • Nessus
  • OWASP Testing Methodology

Nice-to-Have

  • CISSP
  • CREST CRT
  • eWPT
  • Experience supporting federal agencies or DoD customers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

Videos

See all

Related articles

See all