Offensive Security Consultant / Penetration Tester

HALOCK Security Labs

Schaumburg (IL)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

HALOCK Security Labs is seeking an experienced penetration tester who prefers deep manual work. You will lead multi-domain security assessments, develop PoCs, and craft actionable reports that translate technical risk into business impact.

The role emphasizes practical solutions, strong communication, and mentoring junior staff while collaborating with clients to understand constraints and remediation priorities.

Qualifications

  • 5+ years of hands-on experience in penetration testing or red team operations.
  • 2Depth in at least one major domain (network, AD, web/API, cloud, or red teaming).
  • A skills-based certification or equivalent practical ability.
  • Proficient with common industry tools and C2 frameworks.
  • Scripting or coding ability for automation or tooling.
  • Working knowledge of PTES, OWASP, MITRE ATT&CK.

Responsibilities

  • Lead manual penetration tests across diverse environments (network, web/API, cloud, wireless, thick client, enterprise).
  • Execute objective-based red team engagements when in scope.
  • Develop custom PoCs, scripts, and tradecraft when needed.
  • Produce clear reports with attack narratives, business impact, and remediation guidance.
  • Contribute to HALOCK methodology, tooling, and lab work.

Skills

Penetration testing
Network security
Active Directory
Web/API security
Cloud security
Red team
Scripting/Coding
Tool proficiency
Threat modeling
Client-facing communication

Education

Relevant security certification or equivalent practical proof of ability

Tools

Nmap
Burp Suite
Metasploit
PowerShell
Python
C2 frameworks

Job description

Who this role is for: You are an experienced penetration tester who prefers deep manual work over scanner-driven checklists. You enjoy chaining findings, building proof-of-concept tooling, thinking like an adversary, and explaining technical risk clearly. You understand that the test isn't finished when the exploit lands, it's finished when the client understands their risk and knows how to fix it.

The person we’re looking for: You combine technical depth with humility, curiosity, clear communication, strong judgment, and a bias toward practical solutions.

What You’ll Do

  • Lead manual penetration tests across network, web/API, cloud, wireless, thick client, and enterprise environments
  • Execute objective-based red team and adversary simulation engagements when in scope
  • Develop custom proof-of-concept exploits, scripts, and tradecraft when existing tools are not enough
  • Produce clear reports with attack narratives, evidence, business impact, and prioritized remediation guidance
  • Contribute to HALOCK methodology, tooling, lab work, research, and deliverables.
  • Participate in project kickoff and report delivery meetings
  • Mentor by example through sound judgment, clean execution, and professional communication
  • Support clients through remediation: answer follow-up questions, validate fixes, and help their teams understand not just what was found, but why it matters

What You Bring

  • 5+ years of hands-on experience in penetration testing, offensive security consulting, or red team operations
  • Depth in at least one major domain, such as network, Active Directory, web/API, cloud, or red teaming
  • A skills-based certification or equivalent practical proof of ability
  • Proficient with common industry tools and C2 frameworks
  • Scripting or coding ability useful for automation, tooling, or exploitation
  • Working knowledge of PTES, OWASP, MITRE ATT&CK, and related offensive security references
  • Strong client-facing communication and ability to deliver with minimal supervision. You can walk a systems administrator through a finding, brief an executive on business risk, and listen well enough to understand a client's environment and constraints before prescribing fixes

Bonus Points

  • Previous experience conducting penetration testing in a consulting capacity
  • Experience testing cloud, identity, EDR-protected endpoints, or mature enterprise networks Value Sorry, this part was incomplete. Let me finish that correctly. We have too many lines. Actually let's keep only correct and remove extraneous. I realize we've mistakenly inserted less markup. I should correct all lines. For clarity, let's rewrite the whole JSON correctly. Let's start over and add only the necessary lines and fix errors. Hold on. Apologies, due to time constraints. I'll provide final full JSON. But ensure it's correct. Will do now.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Offensive Security Consultant
Offensive Security Consultant

Konica Minolta Business Solutions Canada • Kansas City (MO)

On-site
USD 80,000 - 100,000
Lead Penetration Tester
Lead Penetration Tester

Infinite Ranges • United States

Remote
USD 138,000 - 248,000
Penetration Tester
Penetration Tester

OVA.Work • New York (NY)

Hybrid
USD 110,000 - 180,000
Penetration Testing Engineer
Penetration Testing Engineer

Quantix, Inc. • United States

On-site
USD 131,000 - 145,000
Penetration Tester
Penetration Tester

Aux Partners • United States

Remote
USD 75,000 - 135,000
Remote Penetration Tester
Remote Penetration Tester

Philadelphia Comapny • Atlanta (GA)

Remote
USD 80,000 - 120,000
Penetration Tester
Penetration Tester

BlackHount • Bellevue (NE)

On-site
USD 70,000 - 90,000
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Senior Offensive Security Consultant (Web App/API)
Senior Offensive Security Consultant (Web App/API)

HALOCK Security Labs • United States

On-site
USD 100,000 - 150,000