BreachLock, Inc. Logo

Senior Penetration Tester

Job Description

Company Description

BreachLock is a global leader in Offensive Security including Red Teaming, Continuous Attack Surface Discovery and Penetration Testing services. We help organizations discover, prioritize, and mitigate exposures with evidence-backed Attack Surface Management, Penetration Testing, and Red Teaming. BreachLock provides an attacker’s perspective that goes beyond standard vulnerabilities, enabling organizations to build a comprehensive, proactive defense strategy.

Role Description

Penetration Tester (Mid-Senior) | Full-Time | Remote (US)

As a penetration tester on BreachLock’s US Strategic delivery team, you’ll execute manual, methodology-driven engagements across web applications, APIs, and internal networks — including assumed breach simulations — for enterprise clients. You’ll work directly with delivery leadership, contribute to internal tooling and quality systems, and help raise the bar for the team around you.

Key Responsibilities

  • Execute web application, API and mobile penetration tests with a focus on manual testing beyond automated scanning — business logic, authentication abuse, authorization flaws, and injection chains

  • Conduct internal network assessments, external network assessments and assumed breach engagements, including Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation

  • Leverage frameworks including MITRE ATT&CK, PTES, and OWASP to structure assessments and findings

  • Develop and contribute to internal tooling — automation scripts, reporting utilities, and workflow improvements using Python, Bash, or similar

  • Participate in QA review cycles, providing structured feedback on findings, CVSS scoring accuracy, and report quality

  • Mentor junior testers through technical guidance and finding review

  • Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance

  • 3–5 years of professional penetration testing experience in a delivery or consulting context

  • Strong web application and API testing fundamentals — Burp Suite proficiency, OWASP Top 10 and beyond, authentication and session management testing

  • Solid internal network assessment skills — AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, assumed breach methodology

  • Proficiency in scripting and automation (Python, PowerShell, Bash)

  • Strong written communication — capable of writing clear, accurate, well-scoped findings independently

  • Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus

  • US-based and eligible to work without sponsorship

Preferred

  • Experience with C2 frameworks (Cobalt Strike, Havoc, Sliver, or similar)

  • Active involvement in cybersecurity communities, research, or bug bounty programs

  • Certifications such as OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent practical credentials

  • Experience with SIEM platforms or EDR tools from an adversarial perspective

  • Competitive compensation and performance-based equity opportunities

  • Flexible work hours with hybrid remote options

  • Opportunity to work with international cybersecurity experts

  • Strong career progression in a rapidly expanding early-stage company

  • Exposure to cutting-edge research, tools, and techniques in offensive security

Additional Organization Details

  • BreachLock Website
  • Leadership Team
  • Meet the BreachLockers Video Series
  • Reuters Coverage
  • CEO Interview – Cybercrime Magazine
  • Seemant Sehgal Interview on RT4 & RTLZ
Share this job:
Please let BreachLock, Inc. know you found this job on Remote First Jobs 🙏

10 similar remote jobs

Explore latest remote opportunities and join a team that values work flexibility.

Remote companies like BreachLock, Inc.

Find your next opportunity with companies that specialize in Penetration Testing, Vulnerability Management, Information Security, and Risk Management. Explore remote-first companies like BreachLock, Inc. that prioritize flexible work and home-office freedom.

Praetorian Logo

Praetorian

Provides continuous offensive security, attack surface management, and threat exposure management for enterprises.

View company profile →
Bishop Fox Logo

Bishop Fox

Provides offensive security solutions including penetration testing, red teaming, and attack surface management.

View company profile →
VerSprite Cybersecurity Logo

VerSprite Cybersecurity

Provides threat modeling, penetration testing, and risk management services globally.

View company profile →
SixMap, Inc. Logo

SixMap, Inc.

Preemptive exposure management for organizations, mapping external attack surfaces.

View company profile →
CYE Logo

CYE

201-500 cyesec.com

A continuous exposure management platform that quantifies cyber risk in financial terms to enable mitigation.

View company profile →
JupiterOne Logo

JupiterOne

A cyber asset analysis platform for continuously collecting, connecting, and analyzing asset data for enterprise security.

View company profile →

Project: Career Search

Rev. 2026.6

[ Remote Jobs ]
Direct Access

We source jobs directly from 21,000+ company career pages. No intermediaries.

01

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

02

Advanced Filters

Filter by category, benefits, seniority, and more.

03

Priority Job Alerts

Get timely alerts for new job openings every day.

04

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

21,000+ SOURCES UPDATED 24/7
Apply