Penetration Tester
Job Description
Egis Systems, LLC is seeking an entry level Penetration Tester to perform scoped engagements under supervision, applying Fortified’s methodology to network, system, and application targets. The role emphasizes documenting findings for formal deliverables, pursuing security certifications, and developing foundational exploitation skills alongside professional communication.
Compensation
Salary: USD 88,000 – 100,000 per year.
Location
Remote
Responsibilities
- Execute scoped penetration testing engagements under supervision, covering internal, external, wireless, and application targets, in alignment with Fortified’s methodology.
- Produce accurate, well-documented findings including formal reports, notes, presentations, and appendices, delivered on schedule and reviewed by an IC2 or IC3 practitioner before client submission.
- Report project performance metrics to the Penetration Testing Manager or assigned IC2/IC3 lead; proactively flag delivery risks or blockers.
- Maintain foundational awareness of current threats, vulnerabilities, and exploitation techniques across networks, systems, and applications; develop technical depth over time.
- Pursue relevant industry certifications, with eJPT or CEH as an entry baseline and OSCP targeted within 18 months of hire as a near-term development goal.
- Demonstrate working familiarity with tools such as Kali Linux, Metasploit, NMAP, Burp Suite (Community), and Nessus; continue building proficiency through hands-on engagement work.
- Apply penetration testing methodologies including OWASP, PTES, NIST SP800-115, and MITRE ATT&CK under supervision; understand how methodology and scope influence engagement outcomes.
- Maintain working knowledge of networking technologies, protocols, and network functionality as they relate to penetration testing scope and attack surface analysis.
- Follow Fortified’s rules of engagement and procedures to detect, identify, and exploit vulnerabilities across operating systems, applications, and hardware with minimal client impact.
- Collaborate effectively within a team; communicate engagement status, blockers, and findings to oversight during active projects.
- Provide routine client status updates on a daily or weekly cadence as directed; client communications are reviewed by an IC2 or IC3 practitioner before delivery during the first 90 days and until independent communication readiness is confirmed.
- Accurately record and submit time by required deadlines.
- Monitor communications from Fortified personnel; participate in mandatory training and team and departmental meetings.
- Arrange travel in compliance with company and client travel policies.
- Maintain detailed documentation of customer interactions, engagement actions, and testing notes throughout each project.
- Show awareness of social engineering concepts and their role in engagements; support social engineering components within defined scope as directed.
- Maintain familiarity with Fortified’s core service offerings and make appropriate client recommendations based on those offerings.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent hands-on experience.
- Minimum of 2 years of security or IT experience; lab-based experience and CTF participation accepted at entry level.
- Healthcare IT experience is a plus.
- Strong computer skills in Adobe and Microsoft Office applications (Project, Visio, Word, Excel, PowerPoint).
- Solid understanding of hardware and networking terminology and devices.
- Experience with network security, topology, networking technologies and OSI Model understanding.
- Thorough understanding of current security principles, techniques, and protocols.
- Familiarity with generating and troubleshooting PowerShell, Bash, or Python scripts.
- Ability to work and communicate effectively, professionally, and positively with clients, third-party vendors, and other departments.
- Professionalism and diplomacy to build and maintain relationships throughout the project and beyond.
- Excellent interpersonal skills, with strong written and verbal communication abilities.
- Resourceful and proactive in developing and completing work assignments.
- Strong problem-resolution and critical thinking skills; flexible and self-starting.
- Ability to retain and protect confidential material.
- Baseline requirement of eJPT or CEH; OSCP strongly preferred and expected to be actively pursued within 18 months of hire as a signal for promotion readiness.
- Foundational skills in Kali Linux, Metasploit, and Burp Suite (Community); basic scripting in Python or Bash; foundational understanding of social engineering tactics and their application in engagements.
Technologies
- Kali Linux
- Metasploit
- NMAP
- Burp Suite (Community)
- Nessus
- PowerShell
- Bash
- Python
Working Conditions & Travel
Evenings and weekend hours may be required. Travel as needed.
Similar Jobs
J