bishopfox logo

Penetration Tester

bishopfox

U.S. Remote

Offensive Security

Posted 1 month ago

Job Description

<p><span data-contrast="auto">At Bishop Fox, security&nbsp;isn't&nbsp;just a job—it's&nbsp;our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation. </span><span data-ccp-props="{}">&nbsp;</span></p> <p><span data-contrast="auto">Joining Bishop Fox means collaborating with a curious and dedicated team.&nbsp;You'll&nbsp;tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With&nbsp;nearly 20&nbsp;years of industry&nbsp;contributions—including 16 open-source tools and 50 security advisories published in the past five&nbsp;years—we're&nbsp;committed to making the digital world safer.</span><span data-ccp-props="{}">&nbsp;</span></p> <p><span data-contrast="auto">We’re&nbsp;looking for talented, experienced professional hackers to help us secure some of the world’s most complex software and sophisticated technologies.&nbsp;You’ll&nbsp;be working alongside our US and&nbsp;internationally-based&nbsp;teams supporting clients across multiple industries.                                                   </span><span data-ccp-props="{}">&nbsp;</span></p> <p><strong><span data-contrast="auto">Responsibilities</span></strong><span data-ccp-props="{}">&nbsp;</span></p> <p><span data-contrast="auto">You’re&nbsp;a penetration tester who knows their way around source code.&nbsp;You’ve&nbsp;plundered apps and pillaged networks (legally, of course). You have a passion for hacking and information security. You may also have written a few blog posts about your favorite hacks or have presented at a handful of conferences – with an eye to doing more.</span><span data-ccp-props="{}">&nbsp;</span></p> <p><span data-contrast="auto">With Bishop Fox, your responsibilities would include testing web applications, hacking networks, and reversing software. As a consultant,&nbsp;you’ll&nbsp;work on a variety of projects which include short-term engagements and extended program work with well-established clients.&nbsp;You'll&nbsp;solve challenging technical problems and build creative solutions. As a trusted advisor,&nbsp;you’ll&nbsp;provide your expert opinion to help our clients navigate difficult business decisions.        </span><span data-ccp-props="{}">&nbsp;</span></p> <p><strong><span data-contrast="auto">Requirements</span></strong><span data-ccp-props="{}">&nbsp;</span></p> <ul> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1"><span data-contrast="auto">4+&nbsp;years experience&nbsp;in planning, conducting, and managing web application penetration tests</span></li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">5+ years of application security experience</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Deep understanding of security fundamentals (OWASP), common vulnerabilities, and application security best practices</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Skilled in vulnerability assessment and the development of exploits for diverse targets</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Background in system and network security, authentication and security protocols, and applied cryptography is helpful</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Experience with programming and scripting languages such as Python, Ruby, PowerShell, Java, JavaScript, etc.</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Bonus if you have experience reviewing Golang source code for vulnerabilities</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Proficiency with operating systems- Linux, Windows, MacOS</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Experience with network and system exploitation including modern tactics, techniques, and procedures (e.g. c2 frameworks, EDR bypass, privilege escalation, password cracking, lateral movement, etc.)</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Strong technical reporting and documentation skills</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Advanced relevant academic training, such as a degree in Computer Science or an OSCP, is a definite bonus</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Experience with AWS cloud environments preferred with an understanding of its major technologies, such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambdas, and how to keep them secure</li> <li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="0" data-aria-level="1">Secondary expertise in one or more of the following areas preferred: Cloud Security Assessments, Mobile Application Security Testing, Hybrid Application Assessments, or AI/LLM Security Assessments. Ability to communicate technical findings clearly to both technical and executive stakeholders, including actionable remediation guidance.<span data-ccp-props="{}">&nbsp;</span></li> </ul> <p><span data-contrast="auto">Bishop Fox has always allowed its employees to work remotely, and this role could work anywhere in the United States. Our comprehensive benefits program is tailored to meet your needs at an affordable price. We embrace diversity and an inclusive culture. We value our employees and who they are, which fosters a powerful and collective talent base to successfully serve our clients and the security community with unparalleled&nbsp;expertise. </span><span data-ccp-props="{}">&nbsp;</span></p> <p><em><span data-contrast="auto">Bishop Fox is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.  All new hires must pass a background check as a condition of employment.</span></em><span data-ccp-props="{}">&nbsp;</span></p> <p><span data-contrast="auto">Interested? Apply today!   </span><span data-ccp-props="{}">&nbsp;</span></p>
Apply for this position

Related cybersecurity jobs

bishopfox logo

Partner Marketing Coordinator

Bishopfox

U.S. Remote

Posted 22 days ago

Apply
bishopfox logo

Strategic Outreach Specialist

Bishopfox

U.S. Remote

Posted 22 days ago

Apply
bishopfox logo

Penetration Tester

Bishopfox

Mexico, Remote

Posted 26 days ago

Apply
bishopfox logo

Penetration Tester - Contract

Bishopfox

U.S. Remote

Posted 28 days ago

Apply
bishopfox logo

Engagement Manager

Bishopfox

Mexico, Remote

Posted 28 days ago

Apply
bishopfox logo

Red Team Consultant

Bishopfox

U.S. or Mexico Remote

Posted 1 month ago

Apply

Stay ahead of the curve. Get new infosec jobs in your inbox: