BreachLock
Senior Penetration Tester (US)
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 4 months ago · Found 2h ago
Been open since 4 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
Not stated
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Other
This employer didn't state pay. Jobs like this usually pay around $135k–$215k a year, a typical range taken from 129 senior-level other roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States, Remote"
- Job description states: "US-based"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Company Description
BreachLock is a global leader in Offensive Security including Red Teaming, Continuous Attack Surface Discovery and Penetration Testing services. We help organizations discover, prioritize, and mitigate exposures with evidence-backed Attack Surface Management, Penetration Testing, and Red Teaming. BreachLock provides an attacker's perspective that goes beyond standard vulnerabilities, enabling organizations to build a comprehensive, proactive defense strategy.
Role Description
Penetration Tester (Mid-Senior) | Full-Time | Remote (US)
As a penetration tester on BreachLock's US Strategic delivery team, you'll execute manual, methodology-driven engagements across web applications, APIs, and internal networks — including assumed breach simulations — for enterprise clients. You'll work directly with delivery leadership, contribute to internal tooling and quality systems, and help raise the bar for the team around you.
Key Responsibilities
Execute web application, API and mobile penetration tests with a focus on manual testing beyond automated scanning — business logic, authentication abuse, authorization flaws, and injection chains
Conduct internal network assessments, external network assessments and assumed breach engagements, including Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation
Leverage frameworks including MITRE ATT&CK, PTES, and OWASP to structure assessments and findings
Develop and contribute to internal tooling — automation scripts, reporting utilities, and workflow improvements using Python, Bash, or similar
Participate in QA review cycles, providing structured feedback on findings, CVSS scoring accuracy, and report quality
Mentor junior testers through technical guidance and finding review
Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance
Requirements
3–5 years of professional penetration testing experience in a delivery or consulting context
Strong web application and API testing fundamentals — Burp Suite proficiency, OWASP Top 10 and beyond, authentication and session management testing
Solid internal network assessment skills — AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, assumed breach methodology
Proficiency in scripting and automation (Python, PowerShell, Bash)
Strong written communication — capable of writing clear, accurate, well-scoped findings independently
Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus
US-based and eligible to work without sponsorship
Preferred
Experience with C2 frameworks (Cobalt Strike, Havoc, Sliver, or similar)
Active involvement in cybersecurity communities, research, or bug bounty programs
Requirements
- ·3–5 years of professional penetration testing experience in a delivery or consulting context
- ·Strong web application and API testing fundamentals — Burp Suite proficiency, OWASP Top 10 and beyond, authentication and session management testing
- ·Solid internal network assessment skills — AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, assumed breach methodology
- ·Proficiency in scripting and automation (Python, PowerShell, Bash)
- ·Strong written communication — capable of writing clear, accurate, well-scoped findings independently
Benefits
- ·Competitive compensation and performance-based equity opportunities
- ·Flexible work hours with hybrid remote options
- ·Opportunity to work with international cybersecurity experts
- ·Strong career progression in a rapidly expanding early-stage company
- ·Exposure to cutting-edge research, tools, and techniques in offensive security
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at BreachLock, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 2h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open other roles with comparable remote rules.
Free to apply, no account needed.
Typically $135k to $215k per year · You'll be taken to the employer's careers page.