Bishop Fox
Penetration Tester - Contract
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 5 months ago · Found 11h ago
Been open since 5 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
Not stated
Location
United States only
Timezone
Not stated
Contract
Full-time
Experience
Mid
Category
Other
This employer didn't state pay. Jobs like this usually pay around $80k–$155k a year, a typical range taken from 407 mid-level other roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "U.S. Remote, REM"
- Job description states: "authorized to work in the United States without requirin"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Contract Penetration Tester
At Bishop Fox, security isn't just a job—it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation.
Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions—including 16 open-source tools and 50 security advisories published in the past five years—we're committed to making the digital world safer.
We’re looking for talented, experienced professional hackers to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US and internationally-based teams supporting clients across multiple industries.
Responsibilities
Bishop Fox is looking for experienced contract penetration testers with a primary focus in web application security and strong secondary expertise in cloud, mobile, source code, network, or AI/LLM security.
You’ll work on a range of projects, from short-term assessments to longer-term program engagements with well-established clients. In this role, you’ll identify vulnerabilities, validate risk, develop creative solutions, and clearly communicate findings and remediation guidance to both technical and executive stakeholders. As a trusted advisor, you’ll help clients understand risk and make informed security decisions.
Experience
5+ years of experience planning, conducting, and managing web application penetration tests
Deep understanding of application security fundamentals, OWASP Top 10, common vulnerabilities, and secure development best practices
Experience assessing vulnerabilities and developing exploits across diverse targets
Strong understanding of system and network security, authentication protocols, security protocols, and applied cryptography
Ability to communicate complex technical findings clearly and provide practical remediation guidance to technical and executive audiences
Preferred Experience
Deep experience in at least one of the following:
Cloud Security - Experience assessing AWS cloud environments, including technologies such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambda.
Mobile Application Security - Experience testing iOS and/or Android applications, including mobile application architecture, API communication, data storage, authentication flows, and common mobile security vulnerabilities.
Source Assisted Application Assessments: Experience evaluating applications across multiple layers, including source code, APIs, infrastructure, and integrations. Strong proficiency in Golang is highly preferred, along with familiarity in languages such as Python, Ruby, PowerShell, Java, and JavaScript.
Network Security - Experience with network and system exploitation, including modern tactics, techniques, and procedures such as C2 frameworks, EDR bypass, privilege escalation, password cracking, and lateral movement.
AI/LLM Security - Experience assessing non-deterministic security controls.
Employment Sponsorship
This engagement is for independent contractors (1099) and is not eligible for any form of employment sponsorship. Applicants must be legally authorized to work in the United States without requiring visa sponsorship now or in the future. Applicants must be located in the United States.
All new hires must pass a background check as a condition of employment.
Bishop Fox is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Bishop Fox, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 12h ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open other roles with comparable remote rules.
Free to apply, no account needed.
Typically $80k to $155k per year · You'll be taken to the employer's careers page.