Senior Penetration Tester
Job Description
The Senior Penetration Tester is a remote, senior-level role at Black Lantern Security responsible for leading penetration testing engagements, shaping test strategies, and guiding junior testers throughout engagements.
Responsibilities
- Develop and deliver comprehensive test strategies for evaluating complex, distributed systems.
- Scope and execute penetration tests aligned with client goals and objectives.
- Provide representative tactics, techniques, and procedures (TTPs) suitable for opportunistic, advanced, and sophisticated attackers based on client objectives.
- Offer technical leadership and guidance to junior penetration testers across all assessment phases.
- Prepare clear situation reports and activity summaries for clients and senior leadership.
- Perform verification and validation testing for client mitigations and fixes.
- Develop and deliver walkthroughs, proofs of concept, articles, and formal presentations.
- Attend and present at professional conferences and events as appropriate.
- Conduct independent research to develop novel attack methods.
- Identify new and undisclosed vulnerabilities.
Requirements
- 5+ years of technical cybersecurity experience.
- 5+ years in penetration testing, computer network attack (CNA), or computer network defense (CND).
- 5+ years of experience with scripting languages such as Bash or PowerShell.
- Experience with at least one object-oriented programming language (Python, Ruby, Java, etc.).
- U.S. citizenship and willingness to undergo federal, state, and local background checks and related requirements.
- One or more professional certifications, including OSCP, GPEN, GWAPT, etc.
- Deep knowledge of Windows, Unix, TCP/IP, IDS/IPS, and web content filtering.
- Commitment to the highest standards of honesty and integrity in their work.
- Strong critical thinking skills when addressing complex problems and scenarios.
- Ability to consider emerging vulnerabilities and threats within organizational risk and business impact.
- Capacity to develop novel attack vectors based on newly discovered vulnerabilities.
- Ability to develop home-grown software solutions and utilities for CNA and CND.
- Familiarity with industry standards and best practices including PTES and the MITRE ATT&CK framework.
- Preference for approaches beyond automated, push-button attack tools and utilities.
- Basic understanding of regulatory standards such as HIPAA, PCI-DSS, and GLBA.
Technologies
- bash
- PowerShell
- Python
- Ruby
- Java
- Windows
- Unix
- TCP/IP
- IDS/IPS
- Web content filtering
- PTES
- MITRE ATT&CK Framework
Benefits
- Competitive compensation and benefits package.
- Healthy work-life balance.
- Project-based engagements that align with the strengths of the team.
About Black Lantern Security
- Black Lantern Security is a services oriented organization built around the ingenuity, passion, and determination of our Operators and Analysts.
- There is no single mastermind guiding the culture or outcomes.
- Competitive compensation and benefits.
- Healthy work-life balance.
- Project-based engagements that leverage the team's strengths.
Similar Jobs
J
S