Senior Penetration Tester (US)

BreachLock Inc.

United States

Remote

USD 120,000 - 190,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive compensation & equity
Flexible work hours
Work with international cybersecurity
Career progression
Exposure to cutting-edge tools

Job summary

BreachLock Inc. is seeking a Mid-Senior Penetration Tester for a full-time remote role in the United States. You will execute manual, methodology-driven engagements across web apps, APIs, and internal networks, including assumed breach simulations, for enterprise clients.

You will mentor junior testers, contribute to internal tooling, and collaborate with leadership on scoping and remediation guidance. Strong communication and proficiency with Burp Suite are required.

Qualifications

  • 3–5 years of professional penetration testing experience in a delivery or consulting context.
  • Strong web app and API testing fundamentals with Burp Suite proficiency and OWASP Top 10 knowledge.
  • Internal network assessment skills including AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, and assumed breach methodology.
  • Scripting and automation proficiency (Python, PowerShell, Bash).
  • Strong written communication; ability to write clear, well-scoped findings independently.
  • Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus.
  • US-based and eligible to work without sponsorship.

Responsibilities

  • Execute web application, API, and mobile penetration tests focusing on manual testing beyond automated scanning.
  • Conduct internal and external network assessments and assumed breach engagements, including AD enumeration and lateral movement.
  • Use MITRE ATT&CK, PTES, and OWASP to structure assessments and findings.
  • Develop and contribute to internal tooling and reporting utilities using Python, Bash, or similar.
  • Participate in QA review cycles, provide feedback on findings, CVSS scoring, and report quality.
  • Mentor junior testers through technical guidance and findings reviews.
  • Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance.

Skills

Penetration testing
Web application testing
API testing
Scripting & automation
Technical writing

Education

OSCP/BSCP/CRTO/GWAPT/GPEN or equivalent

Tools

Burp Suite
Python
PowerShell
Bash

Job description

Company Description

BreachLock is a global leader in Offensive Security including Red Teaming, Continuous Attack Surface Discovery and Penetration Testing services. We help organizations discover, prioritize, and mitigate exposures with evidence-backed Attack Surface Management, Penetration Testing, and Red Teaming. BreachLock provides an attacker's perspective that goes beyond standard vulnerabilities, enabling organizations to build a comprehensive, proactive defense strategy.

Role Description
Penetration Tester (Mid-Senior) | Full-Time | Remote (US)

As a penetration tester on BreachLock's US Strategic delivery team, you'll execute manual, methodology-driven engagements across web applications, APIs, and internal networks - including assumed breach simulations - for enterprise clients. You'll work directly with delivery leadership, contribute to internal tooling and quality systems, and help raise the bar for the team around you.

Key Responsibilities
  • Execute web application, API and mobile penetration tests with a focus on manual testing beyond automated scanning - business logic, authentication abuse, authorization flaws, and injection chains
  • Conduct internal network assessments, external network assessments and assumed breach engagements, including Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation
  • Leverage frameworks including MITRE ATT&CK, PTES, and OWASP to structure assessments and findings
  • Develop and contribute to internal tooling - automation scripts, reporting utilities, and workflow improvements using Python, Bash, or similar
  • Participate in QA review cycles, providing structured feedback on findings, CVSS scoring accuracy, and report quality
  • Mentor junior testers through technical guidance and finding review
  • Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance
Requirements
  • 3-5 years of professional penetration testing experience in a delivery or consulting context
  • Strong web application and API testing fundamentals - Burp Suite proficiency, OWASP Top 10 and beyond, authentication and session management testing
  • Solid internal network assessment skills - AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, assumed breach methodology
  • Proficiency in scripting and automation (Python, PowerShell, Bash)
  • Strong written communication - capable of writing clear, accurate, well-scoped findings independently
  • Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus
  • US-based and eligible to work without sponsorship
Preferred
  • Experience with C2 frameworks (Cobalt Strike, Havoc, Sliver, or similar)
  • Active involvement in cybersecurity communities, research, or bug bounty programs
  • Certifications such as OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent practical credentials
  • Experience with SIEM platforms or EDR tools from an adversarial perspective
Benefits
  • Competitive compensation and performance-based equity opportunities
  • Flexible work hours with hybrid remote options
  • Opportunity to work with international cybersecurity experts
  • Strong career progression in a rapidly expanding early-stage company
  • Exposure to cutting-edge research, tools, and techniques in offensive security
Additional Organization Details
  • BreachLock Website
  • Leadership Team
  • Meet the BreachLockers Video Series
  • Reuters Coverage
  • CEO Interview - Cybercrime Magazine
  • Seemant Sehgal Interview on RT4 & RTLZ
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Penetration Tester - Remote, Manual & Red Teaming
Senior Penetration Tester - Remote, Manual & Red Teaming

BreachLock Inc. • United States

Remote
USD 120,000 - 190,000
Competitive compensation & equity
Flexible work hours
Work with international cybersecurity
+2
Senior Penetration Tester - Remote (US), Flexible Hours
Senior Penetration Tester - Remote (US), Flexible Hours

BreachLock Inc. • United States

On-site
USD 90,000 - 120,000
Competitive compensation
Performance-based equity opportunities
Flexible work hours
+2
Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
Sales Engineer - Offensive Security (US Remote)
Sales Engineer - Offensive Security (US Remote)

BreachLock, Inc. • Washington

On-site
USD 120,000 - 180,000
Remote-first
Global team
Penetration Tester
Penetration Tester

Ringside Talent • Columbus (OH)

Hybrid
USD 90,000 - 130,000
OSCP/GPEN sponsorship
Hands-on security culture
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Penetration Tester
Penetration Tester

Ringside Talent Acquisition Partners • Columbus (OH)

Hybrid
USD 90,000 - 140,000
Senior Penetration Tester
Senior Penetration Tester

Dark Wolf Solutions, LLC • United States

Remote
USD 155,000 - 170,000
Senior Penetration Tester – Application Security
Senior Penetration Tester – Application Security

ITR Group • Minneapolis (MN)

On-site
USD 110,000 - 124,000
Principal Penetration Tester
Principal Penetration Tester

Harvard Partners, LLP • Johnston (RI)

On-site
USD 120,000 - 150,000