Penetration Tester / Ethical Hacker (Offensive Security)

Zoho

United States

On-site

USD 83,000 - 165,000

Part time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Fyerx is seeking an experienced Penetration Tester to perform multi-vector offensive security assessments across global networks, web apps and cloud environments. You will emulate APT tactics, discover hidden vulnerabilities, and produce detailed proof-of-concept reports to help engineers and infra teams harden defenses.

You will operate remotely in an offshore capacity and conduct red-teaming, write custom exploits in Python/PowerShell/Bash, and deliver actionable remediation guidance to

Qualifications

  • 4 to 8 years of core cybersecurity experience.
  • 3+ years of dedicated offensive security testing within enterprise environments.
  • Mandatory OSCP or GPEN certification.

Responsibilities

  • Execute network and web app penetration tests using automated and manual methods.
  • Lead red-teaming campaigns and social engineering simulations.
  • Develop exploitation scripts in Python, PowerShell, or Bash.
  • Assess cloud perimeters and API authentication weaknesses.
  • Document vulnerability reports with CVSS scores and remediation steps.
  • Collaborate with blue-team to tune SIEM alerting and defenses.

Skills

Red teaming
Penetration testing
Threat emulation
Python
PowerShell
Bash

Tools

Nmap
Burp Suite
OWASP ZAP

Job description

Penetration Tester / Ethical Hacker (Offensive Security)

Penetration Tester / Ethical Hacker (Offensive Security)

  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 4 to 8 years
  • Relevant Experience Required: 3+ years of dedicated offensive security penetration testing and red teaming experience
  • Mandatory Certification: Offensive Security Certified Professional (OSCP) or GIAC Penetration Tester (GPEN)
Job Summary

We are seeking an experienced Penetration Tester to conduct rigorous, multi-vector offensive security assessments against our global network infrastructure, web applications, and cloud environments. The ideal candidate will emulate advanced persistent threat (APT) tactics, discover hidden exploit vulnerabilities, and write technical proof-of-concept reports to help software engineering and infrastructure teams systematically harden corporate defenses.

Key Responsibilities
  • Execute comprehensive network and web application penetration tests, utilizing automated scanning suites alongside manual exploration tactics to expose system vulnerabilities.
  • Conduct realistic red-teaming simulation campaigns, probing corporate defenses, orchestrating advanced social engineering scenarios, and bypassing physical perimeter monitoring configurations.
  • Develop structural custom exploitation scripts (e.g., Python , PowerShell , Bash) to demonstrate vulnerability severity while respecting operational stability guidelines.
  • Triage and evaluate cloud infrastructure entry vectors, assessing multi-tenant environment perimeters, microservice containers, API authentication weaknesses, and misconfigured access permissions.
  • Document and present highly detailed vulnerability disclosure reports, assigning clear impact scoring (CVSS), defining business risk matrices, and detailing step-by-step technical remediation paths.
  • Perform rigorous post-remediation verification sweeps, re-testing patched software frameworks, validated infrastructure updates, and newly implemented defensive logic barriers.
  • Collaborate closely with blue-team defensive operators, providing specific threat behavior inputs to optimize SIEM monitoring rules and security log alerts.
Requirements
  • 4 to 8 years of core cybersecurity technical experience, with 3+ dedicated years actively performing authorized penetration tests within enterprise frameworks.
  • Deep structural understanding of the OWASP Top 10 web/API flaws, Windows/Linux kernel security architectures, privilege escalation techniques, and active directory exploit vectors.
  • Mandatory certification: OSCP or GPEN.
Preferred Qualifications
  • Offensive Security Certified Expert (OSCE) or Advanced Web Attacks and Exploitation (OSWE) credential.
  • Experience testing complex enterprise platforms like Salesforce networks, custom SAP endpoints, or specialized Workday database connectivity pipelines.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
Penetration Tester
Penetration Tester

Ringside Talent • Columbus (OH)

Hybrid
USD 90,000 - 130,000
OSCP/GPEN sponsorship
Hands-on security culture
Penetration Tester
Penetration Tester

BrothersTech • United States

On-site
USD 95,000 - 150,000
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Penetration Tester
Penetration Tester

BlackHount • Bellevue (NE)

On-site
USD 70,000 - 90,000
Penetration Tester
Penetration Tester

NikSoft Systems Corporation • United States

On-site
USD 120,000 - 170,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Offensive Security Consultant
Offensive Security Consultant

Konica Minolta Business Solutions Canada • Kansas City (MO)

On-site
USD 80,000 - 100,000
Penetration Tester
Penetration Tester

CGVantage • United States

On-site
USD 110,000 - 170,000
Remote Penetration Tester
Remote Penetration Tester

Philadelphia Comapny • Atlanta (GA)

Remote
USD 80,000 - 120,000