Junior Penetration Tester
Job Description
This remote role as a Junior Penetration Tester with Black Lantern Security centers on penetration testing, CNA/CND practices, and threat research, with responsibilities spanning test strategy, reporting, and R&D.
Responsibilities
- Contribute to crafting and delivering test strategies for evaluating complex and distributed systems.
- Provide representative tactics, techniques, and procedures (TTPs) aligned with customer goals for opportunistic, advanced, and sophisticated adversaries.
- Draft clear situation reports and activity summaries for Black Lantern Security clients and senior leadership.
- Perform verification and validation testing of customer mitigations and fixes.
- Develop and deliver walkthroughs, PoCs, technical articles, and formal presentations.
- Participate in professional conferences and events, including presentations when applicable.
- Conduct independent research to develop novel attack methods.
- Investigate to uncover new or undisclosed vulnerabilities through independent research.
Requirements
- Technical Cybersecurity experience.
- Experience in penetration testing, computer network attack (CNA), and/or computer network defense (CND).
- Experience with scripting languages such as bash and/or PowerShell.
- Experience with at least one object-oriented programming language (Python, Ruby, Java, etc.).
- Must be US citizen (willing to submit to federal, state, and local background checks and other requirements).
- Knowledge of Windows, Unix, TCP/IP, IDS/IPS, and web content filtering.
- Adhere to the highest standards of honesty and scientific and business integrity.
- Ability to think critically about complex problems and situations.
- Consider emerging vulnerabilities and threats in the context of organizational risk and business impact(s).
- Develop novel attack vectors based on newly discovered vulnerabilities.
- Develop home-grown software solutions and utilities for CNA and CND.
- Apply industry standards and best practices including PTES and the MITRE ATT&CK Framework.
- Go beyond automated and push-button attack tools and utilities.
- Basic understanding of regulatory standards and requirements including HIPAA, PCI-DSS, and GLBA.
Technologies
- bash
- PowerShell
- Python
- Ruby
- Java
- PTES
- MITRE ATTACK
Benefits
- Competitive compensation and benefits package
- Healthy work-life balance
- Project-based engagements that play to the team's strengths
About Black Lantern Security
- Black Lantern Security is built around the ingenuity, passion, and determination of our Operators and Analysts
- No one single mastermind
- No cult of personality
- Competitive compensation and benefits
- Healthy work-life balance
- Project-based engagements that play to the team's strengths