Bishop Fox logo

Bishop Fox

Penetration Tester

Work from home

Remote role where the employee must remain based in a particular country.

Mexico only

Employer listed it 6 weeks ago · Found 9h ago

Been open since 6 weeks ago, still being checked, but it has been live a while.

Salary

Not stated

Location

Mexico only

Timezone

Not stated

Contract

Full-time

Experience

Mid

Category

Other

This employer didn't state pay. Jobs like this usually pay around $80k–$155k a year, a typical range taken from 407 mid-level other roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Work from home

This is a remote role, but the employee must be based in Mexico. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Mexico, Remote, MEX"
  • Job description states: "authorized to work in Mexico for the duration of emp"

What Nomaders makes of it

  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

At Bishop Fox, security isn't just a job - it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation.

Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions - including 16 open-source tools and 50 security advisories published in the past five years - we're committed to making the digital world safer.

Given our exceptional growth, we are expanding and hiring a Pen Tester to join us on this exciting journey. We’re looking for a talented, experienced professional hacker to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US and internationally-based teams supporting clients across multiple industries.

Who Are You and What You’ll Do

You’re a cybersecurity consultant with a strong offensive security mindset and a passion for understanding how modern applications, cloud platforms, APIs, and emerging technologies operate at a deep technical level. You enjoy uncovering security weaknesses, thinking creatively about attack paths, and helping organizations solve complex security challenges through practical, risk-focused assessments.

At Bishop Fox, you’ll work on a wide variety of security engagements including Cloud Security Assessments, Mobile Application Security Testing, Hybrid Application Assessments (HAA), and AI/LLM Security Assessments. You’ll evaluate modern applications and distributed systems across cloud-native, mobile, backend, and AI-enabled environments.

Your responsibilities will include performing hands-on security testing, analyzing application behavior, reviewing source code, identifying realistic exploitation scenarios, and validating security controls across modern architectures. You’ll work closely with clients and internal teams to deliver high-quality technical assessments and actionable remediation guidance.

As a consultant, you’ll contribute throughout the full engagement lifecycle from scoping and test planning to execution, reporting, and client presentations. Success in this role requires strong technical depth, structured testing methodologies, effective communication skills, and the ability to adapt quickly to new technologies and environments.

Your Experience

4+ years of experience in application security assessments, penetration testing, or offensive security engagements

Strong understanding of application security fundamentals, modern attack techniques, and common vulnerabilities affecting web applications, APIs, mobile applications, and cloud-native environments

Hands-on experience testing REST APIs, including authentication/authorization flaws, IDORs, injection vulnerabilities, session management issues, and business logic flaws

Strength with AWS services and cloud security concepts, including IAM, STS, S3, Lambda, API Gateway, CloudTrail, CloudWatch, and secure communication patterns such as SigV4

Solid understanding of networking and web fundamentals, including HTTP/HTTPS, TCP/IP, DNS, API communication flows, cookies, headers, and related concepts

Experience reviewing source code for security issues in Java, C#, and Python applications

Knowledge of secure coding principles and common risks such as SSRF, insecure deserialization, injection vulnerabilities, sensitive data exposure, and insecure cloud integrations

Understanding of SDLC, CI/CD pipelines, and secure development practices

Experience using security assessment and code review tools such as Burp Suite, Semgrep, Git, AWS CLI, and API testing/debugging tools

Comfortable working across Linux, Windows, and macOS environments

Experience or strong interest in AI/LLM security, including prompt injection, RAG risks, insecure integrations, excessive permissions, and the OWASP Top 10 for LLM Applications

Strong written and verbal communication skills, with the ability to deliver clear, actionable findings and communicate technical risks to both technical and executive stakeholders

Experience following structured testing methodologies, documentation standards, and validation/retesting workflows

Strong collaboration and interpersonal skills when working with security, engineering, and client teams

Ability to manage multiple concurrent engagements while maintaining high-quality deliverables and attention to detail

Requirements

The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Bishop Fox, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 9h ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open other roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $80k to $155k per year · You'll be taken to the employer's careers page.