Ovii Job Board

Senior Penetration Tester (US)

breachlock

United States • Remote - United States • Full-Time • 3-5 years

Posted 2026-05-25 Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

BreachLock seeks a senior penetration tester to lead manual, methodology‑driven security assessments of web, API, mobile and network environments for enterprise clients. The role blends hands‑on testing, internal tooling development, and mentorship within a remote‑first US team.

Role Snapshot

  • Manual web, API & mobile pen testing
  • Network & assumed‑breach assessments
  • Develop internal automation tools (Python/Bash/PowerShell)
  • Mentor junior security testers
  • Collaborate with delivery leadership on scoping & remediation
  • Contribute to QA and reporting quality

Must-Have Requirements

  • 3–5 years professional penetration testing experience
  • Strong web application and API testing fundamentals
  • Burp Suite proficiency
  • OWASP Top 10 knowledge
  • Authentication and session management testing
  • Solid internal network assessment skills (AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations)
  • Proficiency in scripting/automation (Python, PowerShell, Bash)
  • Strong written communication
  • penetration testing
  • web application testing
  • network assessment
  • US‑based and eligible to work without sponsorship

Nice-to-Have Signals

  • Familiarity with PTaaS delivery models
  • Experience with C2 frameworks (Cobalt Strike, Havoc, Sliver)
  • Active involvement in cybersecurity communities, research or bug bounty programs
  • Security certifications (OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent)
  • Experience with SIEM or EDR platforms from an adversarial perspective
  • C2 frameworks
  • community involvement
  • security certifications
  • OSCP
  • BSCP
  • CRTO
  • GWAPT
  • GPEN

Work Setup

  • Location: United States
  • Work mode: REMOTE
  • Remote scope: COUNTRY_RESTRICTED
  • Remote countries: United States
  • Employment type: Full-Time

Eligibility Gates

  • Work authorization: US work authorization without sponsorship
  • Visa sponsorship: no

Not Specified in JD

  • Salary range
  • Visa sponsorship
  • Remote eligibility beyond US
  • Equity details
  • Notice period

What You'll Likely Work On

  • Execute manual penetration tests on web applications, APIs, mobile apps and internal networks, focusing on business‑logic, authentication and injection flaws
  • Perform assumed‑breach engagements, including AD enumeration, lateral movement, privilege escalation and post‑exploitation
  • Structure assessments and findings using MITRE ATT&CK, PTES and OWASP frameworks
  • Develop and enhance internal tooling and automation scripts with Python, PowerShell or Bash
  • Participate in QA review cycles, ensuring accurate CVSS scoring and high‑quality reporting
  • Mentor junior testers through technical guidance and finding reviews
  • Collaborate with delivery leadership on scoping, client kickoff calls and remediation guidance

Good Fit If You Have

  • Enjoys hands‑on security research and community involvement
  • Strong written communication for clear findings
  • Comfortable mentoring and knowledge sharing
  • Interest in building automation tools for security workflows

Skills

  • Web application security testing
  • API security testing
  • Network penetration testing
  • Python scripting
  • PowerShell/Bash automation
  • Burp Suite proficiency
  • MITRE ATT&CK framework
  • PTES methodology
  • OWASP Top 10 knowledge
  • Active Directory enumeration techniques

Remote Eligibility

  • United States