Penetration Tester
Job Description
Convergence Networks is seeking a Penetration Tester (SE) to deliver intermediate and advanced offensive security work that supports client security services. This is a client-facing role focused on vulnerability assessments, penetration testing, and social engineering engagements, with independent delivery of standard testing while coordinating with Security Engineers and Analysts.
Location
Portland, OR (onsite)
Compensation
USD 130,000 - 150,000 per year
Responsibilities
- Plan and execute technical security tasks that support critical elements of client security services.
- Perform Open-Source Intelligence (OSINT) gathering and reconnaissance activities against target organizations.
- Independently conduct standard external and internal network penetration testing engagements.
- Assess Microsoft Active Directory environments, including enumeration, privilege escalation, credential abuse, lateral movement, and common attack paths.
- Conduct authenticated and unauthenticated vulnerability assessments against client environments.
- Validate vulnerabilities via manual testing and, when authorized, controlled exploitation and post-exploitation techniques on Windows and Linux systems.
- Carry out standard web application penetration testing and support advanced application testing based on engagement requirements and experience.
- Depending on experience and specialization, perform wireless security assessments targeting corporate wireless infrastructure.
- Depending on experience and specialization, execute physical penetration testing engagements to evaluate physical security controls.
- Depending on experience and specialization, conduct cloud penetration testing and security assessments within Microsoft Azure and Amazon Web Services (AWS) environments.
- Depending on experience and specialization, perform advanced social engineering or adversary-simulation assessments to evaluate organizational security controls.
- Provide security consulting and technical guidance to clients.
- Lead project kickoff meetings and communicate engagement objectives, scope, and methodologies.
- Present findings, explain security risks, and deliver detailed engagement debriefs to technical and non-technical stakeholders.
- Develop and maintain strong client relationships through professional communication and subject matter expertise.
- Assist clients with remediation planning and security improvement initiatives.
- Produce professional penetration testing reports documenting vulnerabilities, business impact, exploitation details, and remediation recommendations.
- Ensure all reports meet internal quality standards and industry best practices.
- Maintain accurate project documentation and engagement notes across the testing lifecycle.
- Assess and scope customer environments to determine testing requirements and engagement complexity.
- Maintain and secure penetration testing infrastructure, tools, and testing equipment.
- Manage assigned projects, tickets, and deliverables while meeting established deadlines.
- Collaborate with internal teams as needed and contribute to continuous improvement initiatives.
Requirements
- High school diploma or equivalent.
- 3+ years of relevant information technology, cybersecurity, or offensive security experience, including demonstrated hands-on penetration testing or security assessment experience.
- Advanced understanding of computer and networking concepts, services, and protocols including TCP/IP, the OSI networking model, DNS, e-mail flow, operating systems, firewall technologies, network switching, and identity services.
- Ability to communicate effectively with technical and non-technical client stakeholders, orally and in writing.
- Strong documentation and technical reporting skills, including the ability to explain vulnerability evidence, business impact, exploitation details, and remediation recommendations.
- Industry-recognized cybersecurity certification or equivalent demonstrated professional experience. Security+ or a higher-level cybersecurity certification may satisfy this requirement.
- Demonstrated practical penetration testing competency through professional experience, a technical assessment, or a hands-on offensive security certification.
- Foundational or junior practical penetration testing certifications are acceptable evidence of offensive security fundamentals, such as: Practical Junior Penetration Tester (PJPT), eLearnSecurity Junior Penetration Tester (eJPT), or an equivalent hands-on entry-level offensive security certification.
- A junior-level certification alone does not establish intermediate-level competency; candidates relying on a junior credential should demonstrate sufficient hands-on experience to independently conduct standard client penetration testing engagements.
- Must possess or be willing to obtain within the first 12 months of employment a professional-level practical penetration testing certification such as Practical Network Penetration Tester (PNPT), Offensive Security Certified Professional (OSCP/OSCP+), CREST Registered Penetration Tester (CRT), or an approved equivalent.
- Equivalent combinations of professional experience, demonstrated technical capability, education, certifications, labs, research, or other offensive security experience may be considered.
Relevant Technologies
- Kali Linux
- Microsoft Active Directory
- Microsoft 365
- Metasploit
- Windows
- Linux
- Microsoft Azure
- Amazon Web Services (AWS)
- nmap
- Nessus
Benefits
- Competitive salary with profit sharing bonuses
- Great PTO plan with 8 additional paid holidays each year
- Education and certification reimbursement program
- Company-matched 401k plan
- Health insurance options described as among the best available, including free healthcare plans for you and your family
What Successful Performance Includes
- Deliver high-quality penetration testing engagements on time and within scope.
- Produce clear, actionable, and client-focused security reports.
- Build trusted client relationships through professionalism and technical excellence.
- Continuously improve offensive security skills and contribute to growth of the security practice.
- Demonstrate commitment to lifelong learning and professional development.
Skills and Competencies
- Experience using Kali Linux or comparable penetration testing distributions.
- Knowledge of common network ports, protocols, and network topologies.
- Hands-on familiarity with Microsoft Active Directory environments, common attack paths, and associated security controls.
- Working knowledge of Microsoft 365 security controls and cloud security concepts; deeper Azure/AWS testing experience is desirable for specialized engagements.
- Experience working with exploitation frameworks such as Metasploit.
- Understanding of post-exploitation, privilege escalation, credential access, and lateral movement techniques on Windows and Linux systems.
- Ability to perform vulnerability analysis, validate findings through manual testing, and separate exploitable issues from scanner output and false positives.
- Ability to independently plan and execute standard internal and external network penetration tests within approved scope and rules of engagement.
- Strong written and verbal communication skills.
- Ability to translate technical findings into business-relevant risk discussions.
- Excellent problem-solving and analytical thinking abilities, including creative approaches to challenges.
- Self-motivated ability to work independently, with strong time management and organizational skills.
- Ability to collaborate effectively with internal teams and external stakeholders.
Helpful Qualifications
- Associate degree or higher in Information Technology, IT Assurance, or Information Security (Cybersecurity).
- Certified Ethical Hacker (CEH), CEH Practical, or CEH Master.
- CompTIA PenTest+ or other supporting cybersecurity/offensive security certifications.
- Professional or advanced offensive security certifications including PNPT, OSCP/OSCP+, CREST CRT, GPEN, advanced OffSec or CREST certifications, or other recognized practical penetration testing credentials.
- Specialized certifications in red teaming/adversary simulation (including RTO/CRTO), web application testing, Active Directory exploitation, cloud security testing, wireless security, or social engineering.
- Advanced knowledge and experience with utilities such as nmap, Nessus, and Kali Linux.
Work Environment
- Typical working hours include Monday through Friday, 8 AM to 5 PM, with off-hours work during projects.
- Expected weekly workload is typically about 40-45 hours.
- In-office, hybrid, and remote options are available, with accommodations based on preferred work style.
- Occasional onsite travel may be required for company meetings, visits to client sites, and assessments.
- Remote work requires willingness to travel.
- Essential functions include standing, walking, sitting, using hands, seeing, reaching, talking, and hearing.
- May need to lift and/or move up to 50 pounds occasionally.
- Reasonable accommodations may be made for individuals with disabilities.
- Some after-hours work will be required.
- Work likely can be completed remotely.
Performance Feedback
- 90-day, six-month, and annual (12-month) performance reviews, with yearly reviews including performance and salary review.
- Bi-weekly 1:1 meeting with the Manager.
- Manager and employee set performance review goals.
Company Feedback Process
- A 60-day check-in after the start date to confirm onboarding support and identify gaps.
- An opportunity to share feedback to course-correct and improve the onboarding process.
- Annual stay interview to provide unfiltered, honest feedback in a safe environment.
- Regularly scheduled 1:1 meetings with a Team Leader.
- Leadership Team outings for lunch, including for employees who do not report directly to leadership.
- 100% open-door policy to Leadership and Human Resources.
Education
High school diploma or equivalent