Senior Penetration Tester (US)
Quick Summary
Company Description BreachLock is a global leader in Offensive Security including Red Teaming, Continuous Attack Surface Discovery and Penetration Testing services. We help organizations discover,
BreachLock is a global leader in Offensive Security including Red Teaming, Continuous Attack Surface Discovery and Penetration Testing services. We help organizations discover, prioritize, and mitigate exposures with evidence-backed Attack Surface Management, Penetration Testing, and Red Teaming. BreachLock provides an attacker's perspective that goes beyond standard vulnerabilities, enabling organizations to build a comprehensive, proactive defense strategy.
Responsibilities
~1 min read- →Execute web application, API and mobile penetration tests with a focus on manual testing beyond automated scanning — business logic, authentication abuse, authorization flaws, and injection chains
- →Conduct internal network assessments, external network assessments and assumed breach engagements, including Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation
- →Leverage frameworks including MITRE ATT&CK, PTES, and OWASP to structure assessments and findings
- →Develop and contribute to internal tooling — automation scripts, reporting utilities, and workflow improvements using Python, Bash, or similar
- →Participate in QA review cycles, providing structured feedback on findings, CVSS scoring accuracy, and report quality
- →Mentor junior testers through technical guidance and finding review
- →Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance
Requirements
~1 min read- 3–5 years of professional penetration testing experience in a delivery or consulting context
- Strong web application and API testing fundamentals — Burp Suite proficiency, OWASP Top 10 and beyond, authentication and session management testing
- Solid internal network assessment skills — AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, assumed breach methodology
- Proficiency in scripting and automation (Python, PowerShell, Bash)
- Strong written communication — capable of writing clear, accurate, well-scoped findings independently
- Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus
- US-based and eligible to work without sponsorship
Nice to Have
~1 min read- Experience with C2 frameworks (Cobalt Strike, Havoc, Sliver, or similar)
- Active involvement in cybersecurity communities, research, or bug bounty programs
- Certifications such as OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent practical credentials
- Experience with SIEM platforms or EDR tools from an adversarial perspective
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- May 25, 2026
- First seen
- September 28, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 25%
- Scored at
- September 28, 2026
Signal breakdown
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.