Penetration Tester
Job Description
Convergence Networks is hiring a Penetration Tester (SE) to support client security services through intermediate and advanced offensive security work. This role involves hands-on penetration testing, vulnerability validation, and client-facing communication, with collaboration across Security Engineers and Analysts.
Responsibilities
- Plan and execute technical security tasks that are core components of client security services.
- Perform Open-Source Intelligence (OSINT) gathering and reconnaissance against target organizations.
- Independently conduct standard external and internal network penetration testing engagements.
- Assess Microsoft Active Directory environments, including enumeration, privilege escalation, credential abuse, lateral movement, and common attack paths.
- Carry out authenticated and unauthenticated vulnerability assessments across client environments.
- Validate vulnerabilities through manual testing and, when authorized, controlled exploitation and post-exploitation techniques on Windows and Linux systems.
- Conduct standard web application penetration testing and support advanced application testing based on engagement requirements and experience.
- Depending on experience and specialization, complete wireless security assessments against corporate wireless infrastructure.
- Depending on experience and specialization, execute physical penetration testing engagements to evaluate physical security controls.
- Depending on experience and specialization, perform cloud penetration testing and security assessments within Microsoft Azure and Amazon Web Services (AWS) environments.
- Depending on experience and specialization, deliver advanced social engineering or adversary-simulation assessments to evaluate organizational security controls.
- Provide security consulting and technical guidance to clients.
- Lead project kickoff meetings and communicate engagement objectives, scope, and methodologies.
- Present findings and deliver engagement debriefs to technical and non-technical stakeholders.
- Develop and maintain strong client relationships using professional communication and subject matter expertise.
- Assist clients with remediation planning and security improvement initiatives.
- Produce professional penetration testing reports documenting vulnerabilities, business impact, exploitation details, and remediation recommendations.
- Ensure reports meet internal quality standards and industry best practices.
- Maintain accurate project documentation and engagement notes throughout the testing lifecycle.
- Assess and scope customer environments to determine testing requirements and engagement complexity.
- Maintain and secure penetration testing infrastructure, tools, and testing equipment.
- Manage assigned projects, tickets, and deliverables while meeting established deadlines.
- Collaborate with internal teams as required and contribute to continuous improvement initiatives.
Required Qualifications
- High school diploma or equivalent.
- 3+ years of relevant information technology, cybersecurity, or offensive security experience, including demonstrated hands-on penetration testing or security assessment experience.
- Advanced understanding of computer and networking concepts, services, and protocols, including TCP/IP, OSI model, DNS, e-mail flow, operating systems, firewall technologies, network switching, and identity services.
- Ability to communicate effectively with technical and non-technical client stakeholders, orally and in writing.
- Strong documentation and technical reporting skills, including the ability to explain vulnerability evidence, business impact, exploitation details, and remediation recommendations.
- Industry-recognized cybersecurity certification or equivalent professional experience. Security+ or a higher-level cybersecurity certification may satisfy this requirement.
- Demonstrated practical penetration testing competency through professional experience, a technical assessment, or a hands-on offensive security certification.
- Foundational or junior practical penetration testing certifications are acceptable evidence of offensive security fundamentals, including PJPT, eJPT, or an equivalent hands-on entry-level offensive security certification.
- A junior-level certification alone does not establish intermediate-level competency; candidates must also demonstrate sufficient hands-on experience to independently conduct standard client penetration testing engagements.
- Must possess or be willing to obtain within the first 12 months of employment a professional-level practical penetration testing certification such as PNPT, OSCP/OSCP+, CRT, or an approved equivalent.
- Equivalent combinations of professional experience, demonstrated technical capability, education, certifications, labs, research, or other offensive security experience may be considered.
Technologies
Kali Linux, Microsoft Active Directory, Microsoft 365, Metasploit, Windows, Linux, Microsoft Azure, Amazon Web Services (AWS), nmap, Nessus, PJPT, eJPT, PNPT, OSCP/OSCP+, CREST CRT, CRT, Security+, Certified Ethical Hacker (CEH), CompTIA PenTest+
Benefits
- Competitive salary with profit sharing bonuses.
- Great PTO plan with 8 additional paid holidays each year.
- Education and certification reimbursement program.
- Company-matched 401k plan.
- Strong health insurance options for you and your family, including free healthcare plans.
- Many teambuilding and company events throughout the year, with families often included.
- Relaxed work environment.
Work Environment
- Typical schedule is Monday through Friday, 8 AM to 5 PM, with various off-hours work during projects.
- Work is typically about 40-45 hours per week.
- In-office, hybrid, and remote options are available, with accommodations for preferred work style.
- Occasional onsite travel may be required for company meetings, visits to client sites, and assessments.
- Must be willing to travel if remote.
- Physical requirements include standing, walking, sitting, using hands, seeing, reaching, talking, and hearing; occasional lifting or moving up to 50 pounds may be required.
- Reasonable accommodations may be made for individuals with disabilities.
- Some after-hours work will be required.
- Work likely can be completed remotely.
Performance and Feedback
- Performance reviews at 90 days, six months, and annually (12 months), with yearly reviews also used for performance and salary decisions.
- Bi-weekly 1:1 meeting with the Manager, with goals set by you and your Manager.
- A 60-day check-in after the start date to confirm onboarding setup and identify any missing information, with an opportunity to share feedback for process refinement.
- Annual stay interview to provide unfiltered, honest feedback in a safe environment.
- Regular 1:1 meetings with a Team Leader.
- Leadership Team lunch outings, even if you do not report directly to them.
- 100% open-door policy to Leadership and Human Resources.
Role Details
- Location: Remote (remote)
- Salary: USD 130,000 - 150,000 per year
- Experience: Minimum 3 years