Penetration Tester

Jobvite, Inc.

United States

Hybrid

USD 130,000 - 165,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401(k) retirement plan
Unlimited PTO
Growth opportunities

Job summary

NinjaOne is seeking a senior penetration tester to strengthen our security program across apps and environments. You will perform controlled testing of web, cloud, and API surfaces and document risks for remediation.

You will collaborate with Engineering, triage bug bounty submissions, and develop custom tools. The role requires strong English communication and up-to-date threat knowledge.

We offer hybrid remote work in the United States, comprehensive benefits, and opportunities for growth.

Qualifications

  • Bachelor's degree in IT, CS, or related field.
  • 8+ years in hands-on pen testing plus cybersecurity experience.
  • Proficient in Burp Suite and related tooling.
  • Experience with CVSS scoring and risk communication.

Responsibilities

  • Perform controlled penetration testing of NinjaOne applications, cloud environments, and infrastructure, documenting risks and remediation steps.
  • Test security of new API endpoints and features per release cycle, prioritizing coverage against timelines.
  • Collaborate with Engineering to validate vulnerabilities, communicate impact, and support secure remediation.
  • Develop custom tools or scripts to support penetration testing, automation, and exploit development.
  • Perform first-pass triage and validation of bug bounty submissions: reproduce issues, assess severity, identify duplicates, route findings.

Skills

Security testing
Threat modeling
Scripting
Documentation

Education

Bachelor's degree in IT/CS or related field

Tools

Burp Suite
Caido
CVSS tooling

Job description

About the Role

The Penetration Tester role is a key part of NinjaOne's core security team, with visibility across the entire organization, from individual developers to executive leadership. You will directly strengthen the security of the NinjaOne platform by identifying and helping resolve technical, security, and architectural vulnerabilities across our applications and environments. The ideal candidate takes a multi-layered approach to uncovering weaknesses in software, web applications, and client-side components to drive meaningful security improvements. This role is also a key contributor to NinjaOne's public bug bounty program, validating externally reported vulnerabilities and working directly with security researchers around the world.

Location: We are flexible on remote working from home, if you are located in the USA and reside in one of the following states: CA, CO, CT, FL, GA, *IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA. We have physical offices in Austin, TX and Tampa, FL, if you prefer a hybrid option.

*Onsite interviews may be required for this role.

What You'll Be Doing
  • Perform controlled penetration testing of NinjaOne applications, cloud environments, and infrastructure, demonstrating exploitability and documenting risks and remediation steps
  • Perform security testing of new and modified API endpoints and features as part of each release cycle, prioritizing coverage against release timelines
  • Collaborate with Engineering to validate vulnerabilities, communicate impact, and support secure design and remediation efforts
  • Develop custom tools or scripts to support penetration testing, automation, and exploit development
  • Perform first-pass triage and validation of bug bounty submissions: reproduce reported issues, assess severity and impact (CVSS), identify duplicates, and route confirmed findings to the appropriate teams
  • Communicate directly with external security researchers in clear, professional written English throughout the report lifecycle
  • Stay current on emerging threats, TTPs, and cybersecurity trends, applying them to evaluate NinjaOne's exposure and guide security initiatives
  • Create clear, comprehensive reports and presentations for both technical and executive stakeholders
  • Promote security awareness across the organization, contributing to policies, best practices, and ongoing security education
  • Other duties as needed
About You
  • Bachelor's degree in Information Technology, Computer Science, or a related field
  • 8+ years of hands-on penetration testing experience, within a broader 5+ years in cybersecurity-related roles
  • Strong understanding of security protocols, cryptography, authentication/authorization, and modern attack techniques
  • Security certifications such as OSCP (highly desired) and/or Security+, CISSP, or CISM are a plus
  • Proficiency with penetration testing tools such as Burp Suite, Caido, and related frameworks
  • Experience validating and scoring vulnerabilities (CVSS) and communicating findings to both technical and non-technical audiences; bug bounty triage or program experience is a strong plus
  • Ability to develop custom testing tools or scripts (Java, Kotlin, C++, Python, or Go)
  • Knowledge of security frameworks and methodologies (OWASP, NIST, BSIMM), threat modeling (STRIDE, DREAD), and system hardening standards (CIS, CSA)
  • Solid understanding of Linux and Windows operating systems, enterprise architecture, and TCP/IP and UDP networking fundamentals
  • Experience testing or exploiting cloud-native applications; understanding cloud security architecture is a plus
  • Strong analytical and problem-solving skills with excellent written and verbal communication; this role communicates directly with external security researchers, engineers, and leadership
About Us

NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years.

What You'll Love
  • A collaborative, kind, and curious community
  • Full-time work that is hybrid remote, honoring your flexibility needs
  • A comprehensive benefits package, including medical, dental, and vision insurance
  • A 401(k) plan to help you prepare for your financial future
  • Unlimited PTO that prioritizes your work-life balance
  • Opportunity for growth and advancement
Additional Information

This position is NOT eligible for Visa sponsorship.

*Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.

Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage, and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington, the base salary hiring range for this position is $130,000 to $165,000 per year.

For roles based in New York, the base salary hiring range for this position is $130,000 to $165,000 per year.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Jobvite, Inc. • Austin (TX)

Hybrid
USD 130,000 - 165,000
Medical, dental, vision insurance
401(k) plan
Unlimited PTO
+1
Senior Software Engineer, Java | Vulnerability
Senior Software Engineer, Java | Vulnerability

NinjaOne • Connecticut

On-site
USD 140,000 - 200,000
Hybrid remote work
Medical, dental, vision insurance
401(k) plan
+1
Senior Software Engineer, Java | Vulnerability
Senior Software Engineer, Java | Vulnerability

NinjaOne • Town of Texas (WI)

On-site
USD 140,000 - 200,000
Medical, dental, vision insurance
401(k) plan
Unlimited PTO
Senior Software Engineer, Java | Vulnerability
Senior Software Engineer, Java | Vulnerability

NinjaOne • North Carolina

On-site
USD 140,000 - 200,000
Hybrid remote
Medical insurance
Dental and Vision
+3
Senior Software Engineer, Java | Vulnerability
Senior Software Engineer, Java | Vulnerability

NinjaOne • Maine

On-site
USD 140,000 - 200,000
Medical Insurance
Dental Insurance
Vision Insurance
+3
Senior Software Engineer | AI Security Engineering
Senior Software Engineer | AI Security Engineering

Jobvite, Inc. • Northern (KY)

On-site
USD 170,000 - 230,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Software Engineer, Java Backend
Senior Software Engineer, Java Backend

Jobvite, Inc. • Northern (KY)

Hybrid
USD 160,000 - 200,000
Medical Insurance
Dental Insurance
Vision Insurance
+3
QA Engineer
QA Engineer

Kardow • United States

On-site
USD 90,000 - 110,000
Medical, dental, vision insurance
401(k) plan
Unlimited PTO
Principal DevOps Engineer, Continuous Delivery
Principal DevOps Engineer, Continuous Delivery

Jobvite, Inc. • United States

Hybrid
USD 200,000 - 260,000
Medical insurance
Dental insurance
Vision insurance
+3
Staff Software Engineer, Java
Staff Software Engineer, Java

NinjaOne • California (MO)

On-site
USD 200,000 - 300,000
Medical, dental, and vision insurance
401(k) plan
Unlimited PTO
+2