Sr. Offensive Security Consultant

Halock Security Labs

Schaumburg (IL)

Hybrid

USD 130,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive bonus potential
Training and paid certification opportunities
Paid time off
Health benefits
401(k)
Long-term disability

Job summary

Halock Security Labs is hiring a Sr. Offensive Security Consultant to conduct web application and API penetration testing. The role requires 6-8 years of experience, strong proficiency in penetration testing tools, and the ability to develop custom solutions. Responsibilities include producing technical reports, contributing to penetration testing frameworks, and participating in client meetings. The position offers a full-time remote work arrangement with excellent benefits, including competitive salary and training opportunities.

Qualifications

  • 6-8 years of experience in manual web application and API penetration testing.
  • Strong knowledge of web application and API security testing tools.
  • Skills-based industry certification (e.g., OSWA, BSCP, ASCP, etc.) preferred.

Responsibilities

  • Conduct web application and API penetration testing using various tools.
  • Develop custom proof-of-concept exploits and tooling.
  • Produce comprehensive technical reports with remediation guidance.

Skills

Penetration testing
Web application security
API security
Python
Bash
Technical troubleshooting
Project management

Education

Formal education in Information Security, Information Technology, Computer Science, Engineering or related discipline

Tools

Penetration testing tools

Job description

Position: Sr. Offensive Security Consultant – Web App/API

Location: United States – Remote

Employment Type: Full Time

Pay Range: $130k-$160k /yr base salary depending on experience/expertise

Key Responsibilities
  • Conduct web application and API penetration testing using a variety of manual methods, tools, and techniques
  • Develop custom proof‑of‑concept exploits and tooling when automated or existing tools are insufficient
  • Produce clear, comprehensive technical reports and executive summaries that outline vulnerabilities, business impact, and remediation guidance
  • Stay current on emerging threats, TTPs, and cyber security trends
  • Contribute to HALOCK’s penetration testing framework, including deliverables, custom script development, testing methods and techniques, and ongoing research
  • Participate in project kickoff and report delivery meetings
  • Model professional standards in client‑facing and internal communications, including being prepared, on time, and responsive during active engagements
Qualifications
  • Minimum of 6-8 years of professional experience in hands‑on manual web application and API penetration testing across a variety of technologies
  • Strong knowledge of web application and API security testing tools
  • Skills‑based industry certification (e.g., OSWA, BSCP, ASCP, etc.)
  • Demonstrated ability to develop custom tooling in Python, Bash, or similar
  • Excellent ability to troubleshoot technical issues
  • Exhibit extensive knowledge of industry standard penetration testing frameworks and methods (e.g., PTES, OWASP, MITRE ATT&CK)
  • Strong organizational skills, including ability to deliver with minimal supervision
  • Strong professionalism and speaking/writing skills
  • Ability to multi‑task without compromising deadlines and assignment expectations
  • Basic project management competencies such as following process and protocol for project delivery, ability to identify project risks, project multitasking, and ability to self‑manage when appropriate
  • Ability to execute assessments as defined in project plans, within assigned budgets and due dates
Preferred / Nice to Have
  • Previous experience conducting penetration testing in a consulting capacity
  • Cross discipline experience in areas such as network penetration testing, adversarial engagements, mobile application testing, and/or source code review
  • Working knowledge of PCI DSS, HIPAA, and SOC 1/2, and the ability to translate offensive security findings into compliance‑relevant risk and remediation guidance
  • Formal education in Information Security, Information Technology, Computer Science, Engineering or related discipline
  • Desire to contribute to HALOCK’s blog and/or speak at industry conferences on occasion

HALOCK offers excellent compensation and benefits packages including competitive bonus potential, training and paid certification opportunities, paid time off, health, dental, 401(k), long‑term disability, conference attendance, and more.

Disclosures
  • HALOCK is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees.
  • All candidates invited to interview will be required to sign a strict confidentiality and non‑disclosure agreement.
  • Full background checks are performed, with consent, on all successful candidates before employment offers can be extended.
  • US citizens and Green Card holders, EAD and TN are encouraged to apply. We are unable to sponsor H1 candidates at this time.
  • No 3rd parties please. Individuals only need apply.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Offensive Security Consultant (Web App/API)
Senior Offensive Security Consultant (Web App/API)

HALOCK Security Labs • United States

On-site
USD 100,000 - 150,000
Senior Penetration Testing Engineer
Senior Penetration Testing Engineer

Alliant Credit Union • Chicago (IL)

Hybrid
USD 92,000 - 145,000
Annual performance bonus
Work from home up to 3 days a week
Paid parental leave
+7
Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Offensive Security Consultant / Penetration Tester
Offensive Security Consultant / Penetration Tester

HALOCK Security Labs • Schaumburg (IL)

On-site
USD 120,000 - 180,000
Offensive Security Consultant
Offensive Security Consultant

Konica Minolta Business Solutions Canada • Kansas City (MO)

On-site
USD 80,000 - 100,000
Remote Senior Web App & API Security Consultant
Remote Senior Web App & API Security Consultant

HALOCK Security Labs • United States

On-site
USD 100,000 - 150,000
Principal Consultant, Offensive Security, Proactive Services (Unit 42)
Principal Consultant, Offensive Security, Proactive Services (Unit 42)

Palo Alto Networks • Burbank (CA)

On-site
USD 151,000 - 208,000
Senior Web App & API Security Consultant (Remote)
Senior Web App & API Security Consultant (Remote)

Halock Security Labs • Schaumburg (IL)

Hybrid
USD 130,000 - 160,000
Senior Penetration Testing Engineer
Senior Penetration Testing Engineer

Alliant Credit Union • Illinois

Hybrid
USD 92,000 - 145,000
Health insurance
Vision & dental
401k with employer match
+2
Senior Penetration Tester
Senior Penetration Tester

JPMorganChase • New York (NY)

On-site
USD 120,000 - 160,000
Comprehensive health care coverage
Retirement savings plan
Tuition reimbursement