- Provide security posture validation through penetration testing of systems on client networks
- Execute external penetration tests, including reconnaissance, enumeration of internet-facing systems and services, vulnerability identification, reporting, and client delivery
- Conduct internal penetration tests of client networks
- Perform application penetration tests of client applications
- Execute social engineering tests, including reconnaissance, campaign pretext design, phishing emails, spoofed logon forms, reporting, and client delivery
- Lead vulnerability assessments and remediation consulting
- Perform vulnerability scans, generate scan reports, and advise on remediation
- Document testing methodologies, technical findings, proof-of-concept evidence, attack chains, and business impact in professional reports
- Stay current on emerging threats, attack techniques, tools, and industry trends through research, training, certifications, lab work, and knowledge sharing
- Maintain compliance with internal quality standards, client confidentiality requirements, and OWASP, PTES, NIST, and MITRE ATT&CK frameworks and methodologies
- Review colleagues’ reports for formatting and narrative errors and provide feedback
- Work alongside experienced security consultants
- Periodically work outside standard hours to accommodate United States client time zones
- Occasionally travel for on-site client visits, projects, and team or company activities
Requirements
- Associates degree in related field required, or equivalent combination of education, certification and experience
- Minimum of 1-2 years of experience managing IT systems in a professional environment required
- CEH, Net+ or similar IT or security industry recognized certification preferred
- General knowledge of Networks, Linux systems, Windows systems, web applications, and scripting languages
- Familiarity with common attack tools, concepts, and frameworks used for reconnaissance, enumeration, vulnerability identification, exploitation, and reporting
- Excellent verbal and written communication skills
- Ability to clearly document technical findings, develop client-ready deliverables, and present complex information professionally
- Demonstrated commitment to exceptional customer service and effective client relationship management
- Ability to translate technical security concepts, risks, and remediation recommendations for business stakeholders and non-technical audiences
- Strong analytical and critical-thinking skills
- Ability to evaluate security weaknesses, validate findings, and recommend practical risk mitigation strategies
- Effective organizational and time management skills
- Ability to manage multiple projects and competing deadlines while maintaining attention to detail
- Proficient with all Microsoft Office Suite products
- Must be located in one of the specified United States states
Core Competencies
Demonstrates expertise in penetration testing, vulnerability assessment, and remediation consulting, with a strong focus on client communication and documentation. Proficient in applying security frameworks such as OWASP, PTES, NIST, and MITRE ATT&CK to ensure compliance and effective risk management.
Highest-signal resume keywords
- Penetration Testing
- Vulnerability Assessment
- Client Relationship Management
- Technical Documentation
- Security Frameworks Compliance
Hard Skills
- Penetration Testing
- Vulnerability Scanning
- Network Security
- Application Security
- Scripting Languages
- Attack Tools
- Risk Mitigation Strategies
- Technical Findings Documentation
- Reconnaissance
- Enumeration
Soft Skills
- Verbal Communication
- Written Communication
- Analytical Skills
- Critical Thinking
- Organizational Skills
Certifications & Qualifications
Industry Keywords
- Client Networks
- Social Engineering
- Phishing
- Vulnerability Identification
- IT Systems Management
Tools & Technologies
- Microsoft Office Suite
- OWASP
- PTES
- NIST
- MITRE ATT&CK