Penetration Tester

Velero

United States

Remote

USD 165,000 - 220,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Velero, a cybersecurity and compliance consultancy, seeks a skilled penetration tester in the United States to assess web, mobile, and API security and translate findings into actionable steps for clients.

Join a team that conducts rigorous testing across cloud and on-prem environments, applies industry standards like GDPR, PCI-DSS, and SOC 2, and communicates complex risks clearly to technical and non-technical audiences.

Qualifications

  • 3+ years of penetration testing across web apps, mobile apps, APIs, and networks.
  • Expertise in internal and external network testing.
  • Knowledge of OWASP Top 10 and MITRE ATT&CK.
  • Familiarity with Burp Suite, Nmap, Metasploit, Wireshark, Nessus.
  • Experience with cloud environments (AWS/Azure/GCP) is a plus.
  • Strong written and verbal communication skills.

Responsibilities

  • Conduct penetration tests on web applications, mobile applications, and APIs to identify vulnerabilities and potential exploits.
  • Perform network penetration testing, including internal and external network assessments, to ensure comprehensive coverage of security weaknesses.
  • Implement social engineering techniques such as phishing campaigns to simulate real-world attacks and identify human-related security risks.
  • Prepare detailed technical reports and provide actionable recommendations based on the results of penetration tests.
  • Collaborate with internal teams and external clients to discuss findings, mitigation strategies, and security best practices.
  • Ensure compliance with relevant security standards and regulations, including GDPR, PCI-DSS, SOC 2, and others.
  • Stay up to date on emerging threats, vulnerabilities, and security best practices.

Skills

Penetration testing
Network security testing
Security reporting
Communication skills
OWASP Top 10
MITRE ATT&CK
Burp Suite
Nmap
Metasploit
Wireshark
Nessus
Cloud security AWS

Tools

AWS
Azure
GCP

Job description

Velero is a cybersecurity and compliance consulting firm helping clients navigate complex regulatory requirements through expert-led assessments, advisory services, and practical security execution. Working across the computer and network security space, we partner with organizations to strengthen their security posture with clear, actionable guidance grounded in real-world risk.

In this role, you will help clients uncover vulnerabilities across a range of environments and contribute to security assessments that support both technical resilience and regulatory readiness. This is an opportunity for a penetration tester who enjoys tackling varied engagements, communicating findings clearly, and translating complex security issues into practical next steps for internal teams and clients.

Responsibilities
  • Conduct penetration tests on web applications, mobile applications, and APIs to identify vulnerabilities and potential exploits.
  • Perform network penetration testing, including internal and external network assessments, to ensure comprehensive coverage of security weaknesses.
  • Implement social engineering techniques such as phishing campaigns to simulate real-world attacks and identify human-related security risks.
  • Prepare detailed technical reports and provide actionable recommendations based on the results of penetration tests.
  • Collaborate with internal teams and external clients to discuss findings, mitigation strategies, and security best practices.
  • Ensure compliance with relevant security standards and regulations, including GDPR, PCI-DSS, SOC 2, and others.
  • Stay up to date on emerging threats, vulnerabilities, and security best practices.
    Required Qualifications:
  • Proven experience (3+ years) in penetration testing across web apps, mobile apps, APIs, and network environments.
  • Expertise in internal and external network penetration testing.
  • Knowledge of common security vulnerabilities and attack vectors, such as those listed in OWASP Top 10 and MITRE ATT&CK.
  • Familiarity with industry-standard tools like Burp Suite, Nmap, Metasploit, Wireshark, Nessus, and others.
  • Experience with cloud environments (AWS, Azure, Google Cloud) is a plus.
  • Strong understanding of GDPR, PCI-DSS, SOC 2, and other regulatory frameworks.
  • Excellent verbal and written communication skills, with the ability to present findings to technical and non-technical audiences.
    Preferred Skills & Certifications:
  • Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), GIAC Penetration Tester (GPEN), or similar certifications.
  • Experience with mobile security frameworks and tools such as OWASP Mobile Security Testing Guide (MSTG).
  • Experience in API security testing, including OAuth and other common API security models.
  • Proficiency in one or more programming/scripting languages (Python, Bash, JavaScript, etc.).

This position offers a flexible, remote contract opportunity for penetration testers looking to work on exciting security challenges in a nearshore environment. If you are a skilled security professional passionate about identifying vulnerabilities and strengthening security,

Why Join Us?
  • Competitive compensation of 120-160 USD per hour.
  • Flexibility of remote work with a nearshore focus.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Penetration Tester for Web, Mobile & API Security
Remote Penetration Tester for Web, Mobile & API Security

Velero • United States

Remote
USD 165,000 - 220,000
Penetration Tester (Florida)
Penetration Tester (Florida)

Packetlabs Ltd. • United States

Remote
USD 90,000 - 150,000
Fully remote (in Florida)
Competitive compensation
Penetration Tester
Penetration Tester

Ringside Talent Acquisition Partners • Columbus (OH)

Hybrid
USD 90,000 - 140,000
Penetration Tester
Penetration Tester

Ringside Talent • Columbus (OH)

Hybrid
USD 90,000 - 130,000
OSCP/GPEN sponsorship
Hands-on security culture
Penetration Tester - Remote Work | REF#299405
Penetration Tester - Remote Work | REF#299405

BairesDev • United States

On-site
CLP 82,267,000 - 127,971,000
Remote work
USD payment
Hardware provided
+3
Penetration Tester
Penetration Tester

NikSoft Systems Corporation • United States

On-site
USD 120,000 - 170,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
Penetration Testing (Fully Remote)
Penetration Testing (Fully Remote)

Confidential • United States

Remote
USD 90,000 - 140,000
Internal Pen Tester - 160027
Internal Pen Tester - 160027

Piper Companies • United States

Remote
USD 175,000 - 210,000
Medical
Dental
Vision
+4
Senior Penetration Tester
Senior Penetration Tester

Dark Wolf Solutions, LLC • United States

Remote
USD 155,000 - 170,000