Penetration Tester
Job Description
Packetlabs is seeking a penetration tester to conduct thorough, tailored security assessments across modern application types and technologies, with a focus on demonstrating real impact and delivering actionable findings. This is a fully remote role based in Texas.
Key Responsibilities
- Conduct penetration testing for web applications, mobile applications, thick clients, and APIs.
- Perform source code review and whitebox penetration testing to prove the impact of application flaws.
- Carry out reverse engineering of mobile and thick client applications.
- When applicable, link application flaws to adjacent environments, including cloud and on-prem AD infrastructure.
- Produce detailed reporting covering findings and remediations for impactful issues.
- Run SAST and DAST assessments across enterprise, SaaS, and custom in-house applications.
- Use scanners effectively, including validation and elimination of false positives.
- Apply a strong understanding of OWASP across Web, API, Mobile, and AI/LLM contexts.
Required Qualifications
- Customer-first mentality with strong communication skills for clients, project managers, and teammates.
- Respond quickly and deliver work on time.
- Take pride in delivered work and treat output as a reflection of quality.
- Investigate findings deeply and continue until impact is proven.
- Demonstrate a proactive approach by moving toward obstacles and discomfort rather than away from them.
- Adapt to changing consulting conditions and expectations.
- Commit to ongoing learning and maintain strong awareness of personal skill development.
- Self-motivated and dependable.
- Humble working style; no tolerance for ego.
- Solid working knowledge of programming languages including C, C#, Python, Objective-C, Java, JavaScript, SQL, and frameworks such as AngularJS.
- Familiarity with web services and data exchange formats including XML, JSON, SOAP, REST, and AJAX.
- Understanding of AI/LLM weaknesses and application flaws related to AI/LLM.
- Extensive experience using an attack proxy, for example Burp Suite.
- Preferred experience: 3 to 5 years working in penetration testing and consulting.
- Graduate of a post-secondary college or university degree program.
- At least two years of experience handling information security-related tasks.
- Professional qualifications (one or more): OSCP, OSWE, BSCP.
- OSCP or Burp is mandatory for the organization.
- Must be located in Texas.
Technologies and Skills
- C, C#, Python, Objective-C, Java, JavaScript, SQL, AngularJS
- XML, JSON, SOAP, REST, AJAX
- Burp Suite
- OSCP, OSWE, BSCP
- OWASP
- SAST, DAST
- AI/LLM
- Cloud and on-prem AD infrastructure
Benefits
- A strong team and working environment
- Competitive compensation and pay for performance
- Employee growth and development
- Fully remote (in Texas)
At-Will Employment
This position is at-will. This job posting does not constitute an employment contract or guarantee of continued employment.