penetration tester in cybersecurity

HireHi

United States

Remote

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Private health insurance
Performance-based bonus
Professional training portal access
Corporate events and amenities
Certification compensation (AWS, PMP,

Job summary

HireHi is seeking a seasoned cybersecurity professional to lead penetration testing across web apps, APIs, networks, and cloud environments. You will plan, execute, document, and present findings to system owners and management, and support remediation efforts.

The role requires 5+ years in cybersecurity with 3+ years hands-on testing, OWASP-aligned assessments, and strong tooling experience (Burp Suite Pro, Nmap, Metasploit).

Qualifications

  • 5+ years of cybersecurity experience with 3+ years hands-on pen testing.
  • Experience testing web apps and APIs per OWASP Top 10, WSTG, ASVS.
  • Experience testing internal/external infrastructure including AD.
  • Proficient with Burp Suite Pro, Nmap, Metasploit, BloodHound, Impacket.
  • Hands-on certification: OSCP/OSWE/OSEP/CRTO/eWPTX/GPEN/GWAPT.

Responsibilities

  • Plan and perform penetration tests of web applications, APIs, internal and external networks, Active Directory, and cloud environments
  • Conduct manual testing beyond automated scanning, including exploitation and privilege escalation within the agreed rules of engagement
  • Validate findings, assess business risk, and produce clear technical and executive reports
  • Present results to system owners and management, and support remediation and retesting
  • Contribute to red teaming or purple teaming exercises with SOC and detection teams
  • Maintain testing methodologies, tools, and templates

Skills

Penetration testing
Web apps & APIs
Infrastructure testing
English proficiency
Security tooling

Education

OSCP/OSWE/OSEP/CRTO/eWPTX/GPEN/GWAPT

Tools

Burp Suite Pro
Nmap
Metasploit
BloodHound
Impacket

Job description

Описание

The project provides cybersecurity and digital services for international organizations in a large, heterogeneous, multi-tenant environment. It strengthens vulnerability management capabilities to identify, assess, prioritize, and mitigate security risks across organizations worldwide. The customer provides digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support, helping organizations modernize technology environments, strengthen security, and improve the reliability and scalability of digital operations.

Задачи
  • Plan and perform penetration tests of web applications, APIs, internal and external networks, Active Directory, and cloud environments
  • Conduct manual testing beyond automated scanning, including exploitation and privilege escalation within the agreed rules of engagement
  • Validate findings, assess business risk, and produce clear technical and executive reports
  • Present results to system owners and management, and support remediation and retesting
  • Contribute to red teaming or purple teaming exercises with SOC and detection teams
  • Maintain testing methodologies, tools, and templates
Требования
  • 5+ Years of cybersecurity experience, including 3+ years of hands-on penetration testing
  • Experience testing web applications and APIs according to OWASP (Top 10, WSTG, ASVS)
  • Experience conducting internal and external infrastructure testing, including Active Directory attacks
  • Working knowledge of standard tools such as Burp Suite Pro, Nmap, Metasploit, BloodHound, and Impacket
  • At least one recognized hands-on certification: OSCP, OSWE, OSEP, CRTO, eWPTX, GPEN, or GWAPT
  • Clean professional records and willingness to undergo background verification
  • Upper-Intermediate or higher English
  • Будет плюсом: hands-on cloud penetration testing (Azure, Microsoft 365, AWS), mobile application testing (Android, iOS), Red Teaming or Purple Teaming experience including familiarity with C2 frameworks, scripting and security tooling skills (Python, PowerShell, Bash), experience with PTES, OSSTMM, or NIST SP 800-115 methodologies, a proven security research track record such as published CVEs or recognized bug bounty findings
Условия

The opportunity to change projects and/or develop expertise in an interesting business domain

Professional, financial, and career growth; mentoring and adaptation systems for each new employee

Opportunity to earn up to an additional 1,000 EUR per month depending on expertise, included in the annual bonus, by participating in company activities

Access to the corporate training portal and its regularly updated knowledge base

Corporate events and amenities, including parties, pizza days, PlayStation, fruit, coffee, snacks, and movies

Certification compensation (AWS, PMP, etc.)

Referral program

Private health insurance and sports compensation, depending on the type of employment

Work locations: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Hungary, Italy, Latvia, Lithuania, Luxembourg, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and The Netherlands

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

penetration tester in iGaming
penetration tester in iGaming

HireHi • United States

Remote
USD 110,000 - 180,000
Оплачиваемый отпуск
Больничные
Возможность профессионального роста
+1
devops engineer for mobile and web applications
devops engineer for mobile and web applications

HireHi • United States

Remote
USD 67,000 - 123,000
Bonus up to 1000 EUR monthly
Professional growth
Mentoring & onboarding
+5
security engineer for HR technology
security engineer for HR technology

HireHi • United States

Remote
USD 150,000 - 210,000
Annual training budget
Pension plan
Travel reimbursement
+3
qa engineer (auto) for enterprise data platforms
qa engineer (auto) for enterprise data platforms

HireHi • United States

Remote
USD 90,000 - 130,000
Удалённая/Гибридная работа
Ежегодный бонус до 1000 EUR
Корпоративные мероприятия
+2
application security engineer in fintech
application security engineer in fintech

HireHi • United States

Remote
USD 110,000 - 150,000
Гибкий график работы
Поддержка благополучия (Wellbeing)
Возможности карьерного роста
+1
devops engineer in cloud infrastructure
devops engineer in cloud infrastructure

HireHi • United States

Remote
USD 120,000 - 180,000
Private health insurance
Remote or hybrid work options
Career growth & mentoring
+5
Penetration Tester - Infrastructure & Red Team
Penetration Tester - Infrastructure & Red Team

Cybersecurity Jobs • Miami (FL)

Hybrid
USD 90,000 - 130,000
Education reimbursement
Volunteer day
Birthday day off
+2
devops engineer in cybersecurity
devops engineer in cybersecurity

HireHi • United States

Remote
USD 68,000 - 113,000
Private health insurance
Training и менторство
Годовой отпуск и больничные
+3
Penetration Tester (Mid+/ Senior)
Penetration Tester (Mid+/ Senior)

UnderDefense Inc. • United States

Hybrid
USD 120,000 - 190,000
Growth opportunities
Competitive salary
Brilliant team
+5
Penetration Tester
Penetration Tester

Remote Jobs • United States

Remote
USD 60,000 - 77,000
Profit sharing (5-12%)
Remote work from Canada
UberEats budget
+4