CybersecurityJobs.io
← Back to all jobs

Job Description

The Penetration Tester role at Security On-Demand is a hands-on, offensive security position focused on delivering end-to-end client engagements within an established scope. The work includes performing network, web, and cloud assessments and producing client-ready deliverables that support clear decision-making and remediation.

Key Responsibilities

  • Conduct internal and external network penetration tests, including enumeration, exploitation, lateral movement, and post-exploitation activities within defined scope.
  • Perform web application assessments aligned to OWASP Top 10 and support API security testing standards.
  • Carry out basic cloud security assessments for AWS, Azure, and GCP, including misconfiguration identification, IAM review, and exposed services enumeration.
  • Apply experience from adversarial engagements such as red team and purple team exercises.
  • Support AI/LLM security assessments covering prompt injection and model abuse scenarios under senior guidance, including OWASP LLM Top 10 coverage.
  • Prepare complete, client-ready findings reports with clear technical narratives, reproduction steps, risk ratings, and remediation guidance.
  • Participate in client kick-off calls and debrief walkthroughs, communicating results professionally to both technical and non-technical stakeholders.
  • Maintain engagement documentation, time tracking, and artifact organization in project management systems.
  • Continue skill development through assigned training, lab environments, and certification advancement.
  • Travel up to 25% of the time may be required.

Required Qualifications

  • 2 to 5 years of professional penetration testing or applied offensive security experience; strong candidates with equivalent demonstrated skills will be considered.
  • Proficiency with standard offensive security toolsets including Nmap, Metasploit, Burp Suite, Nessus/OpenVAS, BloodHound, or equivalents.
  • Solid understanding of networking fundamentals such as TCP/IP, DNS, HTTP/S, AD, and VPNs, along with common vulnerability classes.
  • Familiarity with at least one scripting language, including Python, Bash, or PowerShell, for basic automation and tooling.
  • Exposure to AWS, Azure, or GCP and awareness of common cloud misconfiguration patterns.
  • Solid understanding of AI technology in everyday work activities.
  • Strong written communication skills to produce accurate, professional-quality findings documentation.
  • Hands-on penetration testing certifications such as PNPT (TCM Security), OSCP (Offensive Security), CompTIA PenTest+, or eWPT/eJPT with demonstrated experience.

Technology Areas

  • Penetration testing tools: Nmap, Metasploit, Burp Suite, Nessus, OpenVAS, BloodHound
  • Scripting: Python, Bash, PowerShell
  • Cloud platforms: AWS, Azure, GCP
  • Core concepts: TCP/IP, DNS, HTTP/S, AD, VPNs
  • Assessment frameworks: OWASP Top 10, OWASP LLM Top 10
  • Certifications: PNPT (TCM Security), OSCP (Offensive Security), CompTIA PenTest+, eWPT, eJPT

Department and Employment Details

Department: Offensive Security

Employment type: Full Time

Workplace type: Fully remote

Location: Remote (Remote - United States)

Professional Growth, Location, and Travel

  • Travel may be required up to 25% of the time.
  • Candidates must be U.S. citizens and currently reside within the United States.

Information Security Expectations

  • Understand and follow information security policies and procedures.
  • Remain vigilant by reporting suspicious activity or possible weaknesses in information security.
  • Actively participate in efforts to maintain and improve information security.
  • This role is considered Moderate Risk with potential to view, access, or download restricted/private client/internal data, which must be handled with sensitivity in the most secure manner.
  • HR reserves the right to perform random background/drug screens to support client and Security On-Demand data safety.

Similar Jobs