Senior Penetration Tester
Senior
Cybersecurity Tools
Data Security
Information Security
Information Technology (IT)
InfoSec
Offensive Security
Penetration Testing
Programming
Programming Language
Programming Languages
Project Management
Security
Security Automation
Security Compliance
Security Standards
Security Testing
Security Testing Tools
Job Description
Schellman is hiring a Senior Penetration Tester to support hands-on penetration testing engagements across on-premise and cloud-based networks and applications. In this remote role, you will execute testing procedures, perform analysis, and deliver well-documented results while strengthening your technical skills through mentorship, collaboration, and client-focused delivery.
Role summary
This position emphasizes structured skill development and high-quality client outcomes. You will contribute to practice development and thought leadership while establishing strong working relationships with client personnel throughout the engagement lifecycle.
Key responsibilities
- Comply with Schellman’s code of ethics and professional conduct, methodologies, and applicable policies and procedures
- Meet professional and regulatory standards relevant to assigned service line specialization(s)
- Support Schellman’s company culture and model Schellman values
- Build high-quality client relationships and rapport with client personnel
- Manage client expectations to help ensure outcomes exceed expectations
- Complete assigned duties on time with strong attention to detail
- Collaborate with project team members across the full project lifecycle and keep work aligned with schedules
- Escalate internal issues in a proper and timely manner
- Use discretion and decorum in the timing, form, and content of client communications
- Book travel reservations in a timely manner in accordance with Schellman travel and expense policies
- When qualified and called upon, perform the essential functions of other service delivery positions
- Attend project kick-off and closing meetings
- Execute assigned testing procedures, analyze findings, reach conclusions, document results per company standards, and suggest improvements when applicable
- Draft project deliverables
- Serve as a contact for clients’ basic engagement questions
- Participate in recruiting and candidate interview activities
- Train project team members and acclimate newer team members
- Contribute to Schellman practice development and develop expert knowledge of professional and regulatory standards relevant to the specialization(s)
- Contribute to Schellman thought leadership (for example, articles, webinars, or public speaking)
Required qualifications
- Bachelor’s degree in technology, computer science, or another relevant subject area, or equivalent years of experience related to the duties and responsibilities
- 3+ years of hands-on penetration testing experience
- 1+ year experience in web application penetration testing
- Strong ability to work independently, with teams, and with clients
- Offensive Security Certified Professional (OSCP) (Required)
- Requisite knowledge of applicable technology and security domains
- High attention to detail and quality of work product
- Client service orientation
- Excellent time management, organizational, and verbal and written communication skills
- Ability to work on-site or remotely as a valuable contributor to a collaborative team
- Capacity to manage tasks across multiple projects simultaneously
- Proficiency using Microsoft Word, Excel, and PowerPoint, and Schellman service delivery applications
- Full understanding and application of ethics, independence, and Schellman values
- Proficiency with at least two scripting languages (for example, Python, Bash, JavaScript, PowerShell)
- Demonstrated enthusiasm for information security (for example: GitHub repo, blogs, presentations, conference talks, local security association membership, or participation in free skill-building or hacking challenges such as SANS Holiday Hack, HackerOne CTF, or HackTheBox)
- Competency in common operating systems (for example, Windows, macOS, Linux)
- Understanding of cloud computing models, technologies, and concepts
Technologies and tools
- OSCP, CRTO
- Burp Suite
- Python, Bash, JavaScript, PowerShell
- Microsoft Word, Microsoft Excel, Microsoft PowerPoint
- Windows, macOS, Linux
- GitHub
- SANS Holiday Hack, HackerOne CTF, HackTheBox
Remote work and travel
- Opportunity to work remotely unless otherwise stated in the job requirements
- Some travel annually, which can include in-person training, team meet-ups, and strategy meetings
- Service Delivery team members may travel based on business and client needs
Similar Jobs
J