Penetration Tester - Infrastructure & Red Team
Job Description
Packetlabs offers a role for an ethical hacker who wants hands-on testing, real client impact, and room to grow. This position supports continued learning through paid education and professional development reimbursement, along with a flexible work environment designed to help you do your best work. You can also look forward to paid volunteer day, paid Birthday day off, and paid U.S. public holidays, with a compensation range of USD 90,000 to 130,000 per year (Remote within Texas or Florida, onsite in Florida).
What you’ll do
The Penetration Tester will plan, execute, and report on infrastructure penetration testing and adversary simulation work across enterprise environments. Engagements may cover on-premises, hybrid, and cloud systems, with testing that evaluates security controls by identifying, validating, and demonstrating exploitable vulnerabilities.
- Plan and run infrastructure penetration testing engagements across on-premises, hybrid, cloud, wireless, and enterprise networks.
- Conduct internal and external network penetration testing using manual methodologies and industry-standard offensive security tools.
- Assess enterprise technologies including Active Directory, Microsoft Entra ID (Azure AD), Windows and Linux, virtualization platforms, cloud services, and supporting infrastructure.
- Evaluate cloud environments across AWS, Microsoft Azure, and Google Cloud Platform to identify configuration weaknesses, privilege escalation opportunities, identity risks, and cloud security vulnerabilities.
- Assess containerized environments, Kubernetes, and CI/CD pipelines where applicable.
- Participate in and lead adversary simulation, red team, and objective-based engagements in line with established methodologies and client objectives.
- Execute offensive security operations across the attack lifecycle, including reconnaissance, initial access, persistence, privilege escalation, credential access, lateral movement, defense evasion, command and control, and objective execution.
- Support purple team efforts by collaborating with defensive teams to validate detections, improve monitoring capabilities, and strengthen defensive controls.
- Develop attack scenarios that demonstrate realistic business impact while maintaining client system integrity.
- Produce comprehensive technical reports covering vulnerabilities, attack paths, business impact, risk ratings, and remediation recommendations; present findings to technical and executive stakeholders.
- Provide technical guidance on remediation strategies, security architecture, and defensive improvements, while managing engagement delivery quality, timelines, and client expectations.
- Contribute to improving testing methodologies, internal tooling, technical documentation, and service offerings through research, automation initiatives, internal training, and knowledge-sharing.
Success in this role also includes contributing to technical research and collaborating with consulting teams to strengthen consistency and delivery across the Offensive Security practice.
What you bring
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related discipline; equivalent practical experience will be considered.
- 3+ years of professional experience performing infrastructure penetration testing, red teaming, adversary simulation, or offensive security consulting.
- Demonstrated experience with enterprise infrastructure testing across Windows, Linux, Active Directory, Microsoft Entra ID, cloud platforms, and enterprise networking.
- Experience with internal and external network penetration testing, privilege escalation, Active Directory security assessments, and lateral movement testing.
- Experience assessing cloud environments including AWS, Microsoft Azure, or Google Cloud Platform.
- Strong understanding of enterprise networking, authentication and identity management, cloud security, and offensive security methodologies.
- Experience using industry-standard offensive security frameworks, tools, and tradecraft.
- Excellent technical writing, presentation, and communication skills for technical and executive audiences.
- Industry certifications such as OSCP, OSEP, CRTO, CRTE, CARTP, CARTA, CREST CRT, CREST CCT, PNPT, GPEN, GXPN, or equivalent are an asset; OSCP or equivalent demonstrated technical capability is strongly preferred.
- Experience in red team, purple team, adversary simulation, or threat emulation is an asset.
- Customer-first mentality with rapid responses and on-time delivery.
- Commitment to validating impact, curiosity to dig deeper into findings, and comfort working through obstacles in a consulting environment.
- Self-motivated, dependable, and humble working style.
Technologies you’ll work with
Active Directory, Microsoft Entra ID (Azure AD), Windows, Linux, virtualization platforms, cloud services, AWS, Microsoft Azure, Google Cloud Platform, Kubernetes, CI/CD pipelines, offensive security frameworks, adversary simulation, red team, purple team, and threat emulation.
How success is measured
- Delivery of infrastructure penetration testing and adversary simulation engagements within established quality, budget, and timeline expectations.
- Accuracy, completeness, and technical quality of reports and deliverables.
- Demonstrated expertise across enterprise infrastructure, cloud security, Active Directory, and offensive security methodologies.
- Positive client feedback on technical expertise, communication, and professionalism.
- Contributions to technical research, methodology development, automation, and knowledge-sharing.
- Effective collaboration with Delivery Managers, Project Managers, and consulting team members.
- Ongoing professional development through certifications, research, and continuous technical skill advancement.