Penetration Tester

Techcompass

Northern (KY)

Hybrid

USD 90,000 - 130,000

Full time

30 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote work
Project-based engagements

Job summary

TechCompass in the United States is seeking experienced penetration testers for flexible, project-based engagements. Remote, U.S.-based contractors perform authorized testing across web, API, cloud, and infrastructure environments, delivering clear remediation guidance and detailed reports.

Candidates bring hands-on testing experience, knowledge of attack techniques, and the ability to explain risk to technical and business stakeholders.

Qualifications

  • Hands-on security testing experience beyond vulnerability scanning.
  • Ability to document findings and communicate risk to technical and business stakeholders.
  • Familiarity with testing methodologies and frameworks (OWASP, PTES, MITRE ATT&CK).

Responsibilities

  • Perform authorized penetration tests across web applications, APIs, cloud, and infrastructure.
  • Combine automated tools with manual testing techniques to identify exploitable weaknesses.
  • Document methodology, evidence, and potential business impact; provide remediation guidance.
  • Present findings to clients and walk through remediation steps with technical teams.

Skills

Penetration testing
Vulnerability analysis
Security reporting
Client communication
Independent work

Education

Bachelor's degree in CS
OSCP or equivalent

Tools

Burp Suite
Nmap
Metasploit
BloodHound

Job description

Web, Mobile, API, Cloud & Infrastructure | U.S.-Based

About the Opportunity

At TechCompass, penetration testing is about more than producing a list of vulnerabilities.

Our testers simulate realistic attack paths, validate whether weaknesses can actually be exploited, determine potential business impact, and give clients clear guidance on what needs to change.

We work with organizations at different stages of security maturity, from growing technology companies to established businesses with complex environments. Engagements vary, which means our testers need technical depth, curiosity, sound judgment, and the ability to communicate clearly with clients.

This is an evergreen opportunity. We’re always interested in connecting with experienced U.S.-based penetration testers as our team and client needs grow.

How this works: These are 1099 subcontractor engagements, not W2 employment. Work is project-based and varies in scope and duration by engagement. Remote, U.S.-based.

What You'll Do

Depending on your specialization and the engagement, you may:

  • Scope and perform authorized penetration tests against web applications, APIs, mobile applications, cloud environments, internal networks, external attack surfaces, or other systems.
  • Combine automated tooling with hands‑on manual testing and exploitation techniques.
  • Identify vulnerabilities, insecure configurations, broken access controls, authentication weaknesses, privilege escalation paths, and other exploitable conditions.
  • Evaluate how individual weaknesses could be combined into realistic attack paths.
  • Validate findings to distinguish meaningful risk from scanner noise and false positives.
  • Document testing methodology, evidence, exploitation paths, affected assets, and potential business impact.
  • Develop clear remediation guidance that technical teams can act on.
  • Walk clients through findings and answer questions from technical teams, security leaders, and business stakeholders.
  • Perform retesting to validate remediation when required.
  • Stay current on emerging vulnerabilities, attack techniques, tooling, and changes across modern application and cloud environments.
  • Collaborate with other TechCompass security practitioners when penetration testing is part of a broader security engagement.
What We're Looking For

Strong candidates will typically bring:

  • Approximately 3–5+ years of professional penetration testing, offensive security, application security, security consulting, or closely related experience.
  • Demonstrated experience performing hands‑on security testing, not solely vulnerability scanning.
  • Strong understanding of common attack techniques, vulnerability classes, and exploitation methodologies.
  • Experience documenting findings and producing professional technical reports.
  • The ability to explain vulnerabilities, attack paths, business impact, and remediation clearly.
  • Familiarity with established testing methodologies and resources such as OWASP, PTES, MITRE ATT&CK, or similar frameworks.
  • Experience with common offensive‑security and testing tools appropriate to your area of specialization.
  • Strong problem‑solving skills and the ability to work independently within an agreed scope and rules of engagement.
  • A high standard of professionalism, discretion, and ethical conduct.
  • U.S.-based work authorization and residence.

We are not expecting every penetration tester to be an expert across every technology.

We are interested in candidates with strong capabilities in one or more of the following:

Web Application & API Testing
  • Web application security testing
  • API security and authorization testing
  • Authentication and session management
  • Business logic vulnerabilities
  • OWASP Top 10 and related application attack techniques
  • iOS and/or Android security testing
  • Mobile application data storage and communications
  • Authentication and authorization
  • API interaction and backend testing
  • AWS, Azure, and/or GCP
  • IAM and privilege escalation
  • Storage, compute, serverless, container, and network security
  • Lateral movement and attack‑path analysis within cloud environments
Network & Infrastructure Testing
  • Internal and external penetration testing
  • Active Directory and identity-based attacks
  • Lateral movement
  • Network services, segmentation, and attack‑surface testing

Experience with additional areas such as source‑code review, wireless testing, social engineering, red teaming, container security, Kubernetes, or emerging technologies is also valuable.

Tools & Technical Knowledge

Depending on your specialization, your experience may include tools and technologies such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, cloud‑native security tooling, scripting languages, mobile testing frameworks, or other offensive‑security platforms.

We don’t hire based on a tool checklist. We’re more interested in whether you understand why a vulnerability exists, how to validate it safely, what an attacker could realistically do with it, and how the client should address it.

Certifications such as OSCP, OSWE, OSEP, GPEN, GWAPT, PNPT, or similar credentials are valued but are not a substitute for practical experience.

What Makes a Great TechCompass Tester

The best penetration testers for our team aren’t just technically capable.

They can move from:

“I found a vulnerability.”

to:

“Here’s how an attacker could use it, what it puts at risk, how serious it is in this environment, and what you should do next.”

That ability to connect technical findings to real‑world risk is central to how TechCompass works with clients.

Why Work With TechCompass

TechCompass is a boutique cybersecurity firm focused on expert‑led, practical security work.

Our broader team works across assessments, cloud and product security, security program development, compliance, security engineering, and strategic advisory, giving penetration testers the opportunity to see how offensive‑security findings fit into a client’s larger security program.

You’ll work across varied environments and meaningful security challenges alongside experienced practitioners who value technical depth, clear communication, and work clients can actually use.

Interested in Working With TechCompass?

Whether your specialty is web applications, mobile, APIs, cloud, infrastructure, or a combination, we’d like to hear from you.

Tell us where you’re strongest, the types of environments you’ve tested, and the kind of offensive‑security work you want to take on next.

At TechCompass, we help businesses use technology securely and strategically. We guide teams through practical security decisions, prioritize the right investments, and deliver clear, effective solutions that reduce risk and support long‑term growth.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Experienced Penetration Tester | Web, API & Cloud Security
Experienced Penetration Tester | Web, API & Cloud Security

Techcompass • Northern (KY)

Hybrid
USD 90,000 - 130,000
Remote work
Project-based engagements
Penetration Tester
Penetration Tester

OVA.Work • New York (NY)

Hybrid
USD 110,000 - 180,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Penetration Tester (Web and Cloud)
Penetration Tester (Web and Cloud)

Silpa Consulting LLC • Houston (TX), Northern (KY)

Hybrid
USD 110,000 - 193,000
Penetration Tester
Penetration Tester

SecureIT • Reston (VA)

On-site
USD 95,000 - 160,000
Principal Penetration Tester
Principal Penetration Tester

Harvard Partners, LLP • Johnston (RI)

On-site
USD 120,000 - 150,000
Offensive Security Consultant / Penetration Tester
Offensive Security Consultant / Penetration Tester

HALOCK Security Labs • Schaumburg (IL)

On-site
USD 120,000 - 180,000
Penetration Tester
Penetration Tester

WarCollar Industries, LLC • Herndon (VA)

On-site
USD 110,000 - 180,000
Medical insurance premium coverage
PTO based on billable hours
Federal holidays plus your birthday
+6
Internal Pen Tester
Internal Pen Tester

Piper Companies • United States

Remote
USD 175,000 - 210,000
Comprehensive Benefits
401K
PTO
+2
Penetration Tester
Penetration Tester

BlackHount • Bellevue (NE)

On-site
USD 70,000 - 90,000