Senior Penetration Tester

Trespass Security LLC

Northern (KY)

Hybrid

USD 120,000 - 180,000

Full time

4 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Trespass Security LLC is seeking a senior penetration tester to autonomously plan and execute tests on web apps, APIs, networks, and cloud environments with written authorization and defined engagement rules.

You will clarify scope, document findings, and communicate results to customers, including retesting eligible fixes, while maintaining strong reporting discipline and stakeholder communication.

Qualifications

  • Senior-level experience independently planning and performing penetration tests within written authorization.
  • Depth in web application and API testing, plus practical experience with network and cloud attack surfaces.
  • Ability to validate findings, reason about realistic attack paths, and communicate technical impact without overstating it.
  • Strong report writing and the ability to discuss findings with both technical teams and business stakeholders.
  • Sound judgment around customer data, credentials, evidence, scope boundaries, escalation paths, and stop conditions.
  • Relevant degrees and security certifications are welcome but are not required.

Responsibilities

  • Own the work from context to retest.
  • Perform and document testing across approved web, API, network, and cloud targets.
  • Validate findings, preserve useful evidence, and distinguish verified findings from unconfirmed signals.
  • Communicate through delivery: provide status updates, write reports, lead customer readouts, explain remediation direction, and complete eligible retests.

Skills

Penetration testing
Web application testing
API testing
Network testing
Cloud security testing

Job description

Own authorized penetration tests from scoping input through careful investigation, clear reporting, customer review, and retesting.

The role

You will independently test web applications, APIs, networks, and cloud environments within written authorization and defined Rules of Engagement.

You will help clarify scope, keep customers informed, investigate and validate findings, write useful reports, discuss results, and retest eligible fixes. The work requires technical depth and the judgment to explain what the evidence does—and does not—show.

What you will do

Own the work from context to retest.

Review the business requirement and technical context, identify open questions, and provide practical scoping input before testing begins.

Perform and document testing

Conduct manual, evidence-driven testing across approved web, API, network, and cloud targets while respecting restrictions and stop conditions.

Validate findings

Investigate potential weaknesses, confirm relevant impact, preserve useful evidence, and distinguish verified findings from unconfirmed signals.

Communicate through delivery

Provide clear status updates, write reports, lead customer readouts, explain remediation direction, and complete eligible retests.

What we are looking for

Demonstrated ability matters more than a particular credential.
  • Senior-level experience independently planning and performing penetration tests within written authorization.
  • Depth in web application and API testing, plus practical experience with network and cloud attack surfaces.
  • Ability to validate findings, reason about realistic attack paths, and communicate technical impact without overstating it.
  • Strong report writing and the ability to discuss findings with both technical teams and business stakeholders.
  • Sound judgment around customer data, credentials, evidence, scope boundaries, escalation paths, and stop conditions.
  • Relevant degrees and security certifications are welcome but are not required.

What success looks like

Engagements move from scope to retest without losing technical clarity.
  • Testing covers the authorized targets and important attack paths without crossing documented boundaries.
  • Potential findings are investigated, supported by useful evidence, and written without overstating impact.
  • Customers understand the findings, limitations, remediation direction, and next steps.
  • Eligible fixes are retested against the original finding and documented clearly.
Employment, location, and authorization.
Employment and location

This is full-time W-2 employment and is fully remote from an eligible location in the United States. Regular overlap with core US business hours is required. No routine travel is expected.

Work authorization

Applicants must be currently authorized to work in the United States. Trespass Security is not able to provide employment-based immigration sponsorship for this role.

Hiring process

The process has two conversations and no unpaid take-home project.

  • An introductory conversation about the role, your experience, and the way Trespass works.
  • A technical and final conversation using past work to discuss testing choices, evidence, reporting, and customer communication.

Employment is contingent on completion of a job-related background check conducted in accordance with applicable law. Applicants who need a reasonable accommodation for the application or interview process may email careers@trespasssec.com .

Trespass Security is an equal opportunity employer.

Trespass Security provides equal employment opportunities without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, disability, genetic information, veteran status, or any other status protected by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Penetration Tester
Principal Penetration Tester

Trespass Security LLC • Northern (KY)

Hybrid
USD 140,000 - 190,000
Security Engagement Manager
Security Engagement Manager

Trespass Security LLC • Northern (KY)

Hybrid
USD 110,000 - 160,000
Senior Penetration Tester — Remote, End-to-End Security Testing
Senior Penetration Tester — Remote, End-to-End Security Testing

Trespass Security LLC • Northern (KY)

Hybrid
USD 120,000 - 180,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
Senior Penetration Tester & Technical Lead - Remote
Senior Penetration Tester & Technical Lead - Remote

Trespass Security LLC • Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Penetration Tester (US)
Senior Penetration Tester (US)

BreachLock Inc. • United States

On-site
USD 120,000 - 190,000
Competitive compensation & equity
Flexible work hours
Work with international cybersecurity
+2
Penetration Tester
Penetration Tester

TechCompass • Northern (KY)

Hybrid
USD 90,000 - 130,000
Remote work
Project-based engagements
Remote Penetration Tester
Remote Penetration Tester

Philadelphia Comapny • Atlanta (GA)

Remote
USD 80,000 - 120,000
Principal Penetration Tester
Principal Penetration Tester

Harvard Partners, LLP • Johnston (RI)

On-site
USD 120,000 - 150,000
Penetration Tester (Contract)
Penetration Tester (Contract)

Educate 360 • Northern (KY)

On-site
USD 90,000 - 140,000