Senior Penetration Tester
Core
Evolve security pentesting capabilities to test internal and external facing processes, infrastructure, and applications, demonstrating exploitability to engineering teams and senior leadership.
Role type
Senior IC penetration tester (offensive security)
Builds
Validated security posture for web applications, infrastructure, and cloud-native environments
Domain
Cybersecurity / Offensive Security / Real Estate Technology
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing (web applications, APIs, infrastructure), Vulnerability exploitation, Secure code review, Python/PowerShell scripting, C#/Java/JavaScript/Go code reading, Report writing for business impact, Defense-in-depth strategy
Preferred skills
Active Directory exploitation, C2 frameworks (Cobalt Strike, Sliver, Mythic), Red team/purple team scenario planning, Adversary emulation (MITRE ATT&CK), Cloud-native security testing, Mobile app penetration testing, AI/LLM security testing (prompt injection, agentic risks), CI/CD pipeline security integration
Technologies
Burp Suite, OWASP ZAP, Nmap, Bloodhound, Metasploit, Cobalt Strike, Sliver, Mythic, AWS, Kubernetes, CI/CD pipelines
Responsibilities
Lead penetration tests on web applications and infrastructure using manual and automated techniques; Develop test plans validating vulnerabilities and demonstrating exploitability; Collaborate on purple team exercises to validate controls; Grow pentesting capabilities in infrastructure and cloud-native domains; Recommend remediations addressing root causes; Mentor engineers on offensive techniques and attacker mindset
Seniority
Senior, hands-on IC