- Страна
- США
Откликайтесь
на вакансии с ИИ

Penetration Tester
Отличная вакансия для опытных пентестеров с акцентом на современные технологии и гибкий график. Привлекательные бонусы, такие как безлимитный отпуск и поддержка профессионального обучения, повышают рейтинг.
Сложность вакансии
Роль требует минимум 3 года практического опыта и глубоких знаний в тестировании веб-приложений и сетей. Высокая планка задается необходимостью наличия сертификации OSCP и публичного вклада в ИБ-сообщество.
Анализ зарплаты
Предлагаемая роль соответствует рыночным стандартам для Senior/Middle+ Penetration Tester в США. Учитывая требования к OSCP и 3+ годам опыта, зарплата находится в верхнем сегменте для удаленной работы.
Сопроводительное письмо
I am writing to express my strong interest in the Penetration Tester position at Sprocket Security. With over three years of experience in offensive security and a deep focus on web application testing, I am particularly drawn to your expert-driven Continuous Penetration Testing platform. My background in simulating real-world adversary TTPs and building custom payloads aligns perfectly with your mission to empower enterprises through risk-based defense strategies.
Throughout my career, I have developed a robust toolkit including Burp Suite Pro, Cobalt Strike, and Metasploit, complemented by proficiency in Python and Ruby for automating testing tasks. I am a firm believer in the value of community contribution, having maintained several open-source security tools on GitHub. I am excited about the opportunity to bring my technical expertise and passion for uncovering vulnerabilities to the Service Delivery team at Sprocket Security.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в sprocketsecurity уже сейчас
Присоединяйтесь к команде Sprocket Security и станьте экспертом в области непрерывного тестирования на проникновение!
Описание вакансии
Company Mission - Our mission is to help secure as many companies as possible, by using the best way of doing so, penetration testing. Sprocket Security prioritizes offensive security for enterprises, empowering them to build robust defense strategies based on individual business risk.
How - At Sprocket Security, we've built an expert-driven Continuous Penetration Testing platform that blends cutting-edge automated and manual testing methods.
Your Mission - You will be part of our passionate and innovative Service Delivery team, simulating real-world cyber-attack tactics, techniques, and procedures (TTPs). We look for risks and security vulnerabilities utilized by real-world attackers, and you’ll contribute directly to uncovering and explaining them. This role is ideal for an individual who wants to deepen their craft, learn continuous testing at scale, and grow in their career.
Responsibilities:
- Perform web application testing across a large and diverse client base using established methodologies, and creating your own.
- Perform network and wireless testing methodologies at scale from time to time.
- Discover newly exploitable systems across our fleet of clients. It's fun to test that new vulnerability the day it's released!
- Build payloads and C2 infrastructure that evades defenses.
- Mimic tactics and techniques used by real-world adversaries.
- Show impact with post-exploitation activities.
- Manage our platform by conducting tasks, write findings, and work with clients to help detect and prevent.
- Build scripts, tooling, or templates to improve personal testing efficiency and contribute ideas for future automation in the platform. You'll commonly program in the following languages: Ruby, Python, PowerShell, C# Bash, etc.
- Advanced usage of the following tools: Burp Suite Pro, Nessus, Metasploit, CobaltStrike, etc.
- Manage project lifecycles and present professionally to clients. Kickoff calls, debriefs, etc.
- Work closely with development teams to migrate human-driven tasks into automation.
- Work with AWS, Azure, terraform, ansible, and gitlab pipelines.
Requirements:
Minimum:
- Three or more years of hands-on penetration testing experience.
- One or more years of hands-on web application penetration testing experience.
- Detailed knowledge of identifying and exploiting vulnerabilities in Windows, Linux, and cloud -based systems.
- Programming experience in Ruby, Python, Bash. Bonus (C#, JavaScript, terraform, ansible).
- One publicly available contribution to the security community? (e.g., open-source tool or code on GitHub, published blog posts, conference talk, podcast, research paper etc etc)
- Clear and concise verbal and written skills.
- United States resident
Preferred:
- OSCP or equivalent skills-based certification mandatory, or will need to obtain within 12 months of employment.
- Adversary Simulation experience.
- Has industry involvement by contributes research, open-source projects, or public speaking
- Experience managing or working with management on security projects and teams. Bonus if CISSP certified.
- Remote work acceptable.
- Preferred proximity to Madison, WI
Benefits:
- Unlimited and mandatory PTO for healthy work/life balance.
- Company matched 401k (immediate eligibility, no one should have to wait to start saving).
- 75% company contribution for health insurance for employees and 50% for dependants.
- 100% company contribution for dental and vision.
- Work whatever schedule works best for you. We care about results, not 9-5.
- Hardware and tools of your choice
- Support for your career development with paid training, conferences, certifications, etc.
Location: Remote
Ready to Trailblaze the Cybersecurity Frontier? If you're passionate about cybersecurity and eager to make an impact in the industry, we want you on our team. Apply now at Sprocket Security and join the revolution of safeguarding businesses from cyber threats!
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- Penetration Testing
- Web Application Security
- Python
- Ruby
- Metasploit
- Burp Suite
- Cobalt Strike
- Nessus
- PowerShell
- Bash
- C++
- AWS
- Azure
- Terraform
- Ansible
- GitLab
Возможные вопросы на собеседовании
Проверка практического опыта обхода современных систем защиты.
Расскажите о вашем опыте создания полезной нагрузки (payloads) для обхода EDR или антивирусных решений. Какие техники вы использовали?
Оценка навыков тестирования веб-приложений, что является ключевым требованием.
Опишите ваш процесс тестирования сложного одностраничного приложения (SPA). На каких уязвимостях вы фокусируетесь в первую очередь?
Проверка навыков автоматизации и разработки собственных инструментов.
Какие задачи в процессе пентеста вы обычно автоматизируете с помощью Python или Ruby? Можете привести пример написанного вами скрипта?
Оценка способности работать в облачных средах.
С какими специфическими векторами атак в средах AWS или Azure вы сталкивались и как проводили их эксплуатацию?
Проверка навыков коммуникации и взаимодействия с клиентами.
Как вы объясняете критическую техническую уязвимость нетехническому руководству клиента, чтобы они поняли бизнес-риск?
Похожие вакансии
Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)
Исследователь безопасности Android
Эксперт по защите периметра (WAF)
DevOps-инженер/ИБ (devops engineer, information security)
Application Security Еngineer (AppSec)
Инженер по сетевой безопасности
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- США