Job Description
Ovii's Interpretation of the Role
BreachLock seeks a senior penetration tester to lead manual, methodology‑driven security assessments of web, API, mobile and network environments for enterprise clients. The role blends hands‑on testing, internal tooling development, and mentorship within a remote‑first US team.
Role Snapshot
- Manual web, API & mobile pen testing
- Network & assumed‑breach assessments
- Develop internal automation tools (Python/Bash/PowerShell)
- Mentor junior security testers
- Collaborate with delivery leadership on scoping & remediation
- Contribute to QA and reporting quality
Must-Have Requirements
- 3–5 years professional penetration testing experience
- Strong web application and API testing fundamentals
- Burp Suite proficiency
- OWASP Top 10 knowledge
- Authentication and session management testing
- Solid internal network assessment skills (AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations)
- Proficiency in scripting/automation (Python, PowerShell, Bash)
- Strong written communication
- penetration testing
- web application testing
- network assessment
- US‑based and eligible to work without sponsorship
Nice-to-Have Signals
- Familiarity with PTaaS delivery models
- Experience with C2 frameworks (Cobalt Strike, Havoc, Sliver)
- Active involvement in cybersecurity communities, research or bug bounty programs
- Security certifications (OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent)
- Experience with SIEM or EDR platforms from an adversarial perspective
- C2 frameworks
- community involvement
- security certifications
- OSCP
- BSCP
- CRTO
- GWAPT
- GPEN
Work Setup
- Location: United States
- Work mode: REMOTE
- Remote scope: COUNTRY_RESTRICTED
- Remote countries: United States
- Employment type: Full-Time
Eligibility Gates
- Work authorization: US work authorization without sponsorship
- Visa sponsorship: no
Not Specified in JD
- Salary range
- Visa sponsorship
- Remote eligibility beyond US
- Equity details
- Notice period
What You'll Likely Work On
- Execute manual penetration tests on web applications, APIs, mobile apps and internal networks, focusing on business‑logic, authentication and injection flaws
- Perform assumed‑breach engagements, including AD enumeration, lateral movement, privilege escalation and post‑exploitation
- Structure assessments and findings using MITRE ATT&CK, PTES and OWASP frameworks
- Develop and enhance internal tooling and automation scripts with Python, PowerShell or Bash
- Participate in QA review cycles, ensuring accurate CVSS scoring and high‑quality reporting
- Mentor junior testers through technical guidance and finding reviews
- Collaborate with delivery leadership on scoping, client kickoff calls and remediation guidance
Good Fit If You Have
- Enjoys hands‑on security research and community involvement
- Strong written communication for clear findings
- Comfortable mentoring and knowledge sharing
- Interest in building automation tools for security workflows
Skills
- Web application security testing
- API security testing
- Network penetration testing
- Python scripting
- PowerShell/Bash automation
- Burp Suite proficiency
- MITRE ATT&CK framework
- PTES methodology
- OWASP Top 10 knowledge
- Active Directory enumeration techniques
Remote Eligibility
- United States