CybersecurityJobs.io
← Back to all jobs

Job Description

Taylor Corporation is seeking a Penetration Tester to conduct penetration tests and vulnerability assessments across network, application, cloud, and wireless environments. The role includes planning and executing testing, analyzing results, advising on remediation, and validating remediation effectiveness.

Location and Work Model

  • Location: North Mankato, MN
  • Work arrangement: Onsite

Salary

  • Compensation: USD 97,000 - 120,000 per year

Experience

  • Minimum experience: 3 years

Responsibilities

  • Partner with business and technical stakeholders to define test objectives, scope, and rules of engagement.
  • Design and execute internal and external penetration tests and vulnerability assessments across network, web applications, APIs, cloud, wireless, and segmentation, aligned to applicable industry standards, regulatory requirements, and contractual obligations.
  • Perform manual validation and controlled exploitation to confirm vulnerabilities, identify attack paths, and separate penetration testing outcomes from automated vulnerability scanning.
  • Create test plans and run reconnaissance, manual testing, and safe exploit validation while protecting test data and removing testing artifacts.
  • Communicate results, support remediation validation, and complete retesting after remediation.
  • Use recognized testing methodologies and requirements, including OWASP Web Security Testing Guide, OWASP ASVS when applicable, NIST SP 800-115, PTES or a comparable methodology, and PCI DSS, along with relevant customer or contractual requirements.
  • Follow approved rules of engagement, including test windows, escalation procedures, data-handling requirements, and stop-testing conditions.
  • Coordinate potentially disruptive activity with system owners and immediately report unintended impacts or exposure of sensitive information.
  • Provide remediation consultation for penetration test findings.
  • Conduct risk assessments for networks and applications, wireless technologies, and other technical environments.
  • Document findings and recommendations using company-standard templates, producing both detailed technical reports and concise executive summaries.
  • Develop, document, and maintain penetration test procedures, finding templates, and supporting documentation.
  • Review and provide input on penetration test reports authored by other penetration testers.
  • Report to management regarding residual risk, vulnerabilities, and other security exposures, including misuse of information assets and noncompliance.
  • Safeguard credentials, test data, customer information, and exploit evidence; follow responsible disclosure and company ethics requirements; and perform testing only within expressly authorized scope.
  • Stay current on security trends, best practices, and emerging issues.
  • Perform other duties as assigned.

Required Qualifications

  • A current, industry-recognized penetration testing certification required at time of hire (examples include OSCP, PNPT, GPEN, GWAPT, eWPT, or comparable).
  • Minimum three years of hands-on experience performing penetration tests in enterprise environments.
  • Minimum three years of related experience in information technology, application development, system administration, or comparable technical discipline (may overlap with penetration testing experience).
  • Experience using common penetration testing and vulnerability assessment tools, including Nmap, Burp Suite Professional, HCL AppScan, Nessus, Metasploit, Kali Linux, or comparable technologies.
  • Working knowledge of TCP/IP, DNS, routing, firewalls, network segmentation, HTTP/S, authentication, session management, and APIs.
  • Hands-on experience with Windows, Linux, Active Directory, cloud platforms, and scripting using Python, PowerShell, Bash, or comparable languages.
  • Knowledge of common vulnerability classes, attack paths, defensive controls, and secure software development principles.
  • Strong collaborative approach for cross-functional and remote teams.
  • Ability to operate in a fast-paced, fluid environment.
  • Self-directed, decisive, and action-oriented with the ability to work under minimal supervision and meet deadlines.
  • Commitment to complete, accurate, and timely documentation and detailed tracking.
  • Strong written and verbal communication skills, including the ability to present technical issues for nontechnical audiences.
  • Analytical and problem-solving skills, with the ability to manage multiple efforts concurrently and balance priorities across security, IT, and the business.
  • Ability to clearly communicate security risk, respectfully challenge assumptions when appropriate, and support documented management risk decisions.
  • Ability to interface effectively with vendors, customers, IT, and business personnel.
  • Demonstrated integrity and strong business ethics.

Technologies

  • OSCP, PNPT, GPEN, GWAPT, eWPT
  • Nmap, Burp Suite Professional, HCL AppScan, Nessus, Metasploit, Kali Linux
  • OWASP Web Security Testing Guide, OWASP ASVS
  • NIST SP 800-115, PTES, PCI DSS
  • Windows, Linux, Active Directory, cloud platforms
  • Python, PowerShell, Bash
  • TCP/IP, DNS, HTTP/S, authentication, session management, APIs

Benefits

  • Choice of several health plans
  • Dental
  • Vision
  • Wellness programs
  • Life and disability coverage
  • Flexible spending accounts
  • Health savings accounts
  • 401(k) plan with company match
  • Paid time off (PTO)
  • 64 hours of annual holiday pay

Work Authorization

  • Candidates must be authorized to work in the United States without the need for employer sponsorship.
  • This position must be performed within the United States.
  • Candidates must be legally authorized to work in the United States and able to satisfy applicable customer access, background-screening, or clearance requirements.

Work Schedule

  • Monday through Friday business hours.
  • Some cases may require evening, overnight, or weekend work to support scheduled testing outside normal business hours.

Travel

  • Limited travel may be required to perform on-site penetration tests.

Similar Jobs