CybersecurityJobs.io
← Back to all jobs

Job Description

The Penetration Tester role at Trofi Security is an onsite position based in Lafayette, Colorado. The role centers on planning and executing information security testing, including black box, grey box, and white box assessments, with a strong emphasis on hands-on exploitation, vulnerability discovery, and communicating findings clearly. A minimum of five years of information security and penetration testing experience is required.

Responsibilities

  • Plan and execute information security testing across black box, grey box, and white box engagement models.
  • Perform hands-on exploitation and vulnerability discovery, and clearly communicate findings to stakeholders.
  • Apply creative problem solving and rigorous methodology to identify security weaknesses within authorized scope.
  • Demonstrate the ability to operate independently or as part of a team to deliver testing engagements.

Requirements

  • 5+ years of information security experience with application and network penetration testing.
  • Deep understanding of web frameworks, including XML, SOAP, JSON, and AJAX.
  • Experience with scripting languages such as Bash, Perl, Python, Ruby, VBScript/WScript, or PowerShell.
  • Experience exploiting web applications and services.
  • Working knowledge of firewalls and other network security products.
  • Experience with .NET web application frameworks and languages.
  • Understanding of C, C#, Objective-C, and Java.
  • Familiarity with web proxy tools.
  • Familiarity with penetration testing tools such as Kali Linux, Nexpose, Nessus, Nmap, Metasploit, vulnerability scanners, tcpdump, and Wireshark.
  • Excellent written and oral communication skills.
  • Self-motivated and able to work both independently and with a team.
  • Willing to travel up to 50% of the time.

Technologies

  • XML
  • SOAP
  • JSON
  • AJAX
  • Bash
  • Perl
  • Python
  • Ruby
  • VBScript / WScript
  • PowerShell
  • .NET
  • C
  • C#
  • Objective-C
  • Java
  • Web proxy tools
  • Kali Linux
  • Nexpose
  • Nessus
  • Nmap
  • Metasploit
  • tcpdump
  • Wireshark
  • Rapid7 Nexpose
  • BurpSuite Pro
  • OSSTMM
  • OWASP
  • NIST Special Publications

Highly Desirable Skills and Qualifications

  • Familiarity with Open Source Security Testing Methodology Manual (OSSTMM), OWASP, and NIST Special Publications.
  • Experience using Rapid7 Nexpose and Metasploit, and BurpSuite Pro.
  • Experience leading or participating in Red Team engagements.
  • Knowledge of applied cryptographic protocols.
  • Certifications such as CEH, CPT, CISSP, OSCP/E, GWAPT, GPEN, GXPN.
  • Experience with debuggers and disassemblers.
  • Experience in exploit development.
  • Experience in hardware hacking or embedded systems hacking.
  • Advanced degree in an IT-related field is a plus.

Similar Jobs