We are looking for a Mid Penetration Tester to deliver penetration tests to Thoropass customers, including vulnerability assessments, web app pentests, network pentests, and API pentests.
This role will be a player-coach, responsible for delivering our first batch of customer-facing pentest reports. As we scale the offering, this role will also mentor junior resources to deliver consistently high-quality pentests. The ideal candidate will be equal-parts penetration tester, strategic thinker, and operational doer with a passion for solving complex challenges and delivering measurable impact for our company and customers.
About You
- You adopt the mindset of an attacker, delving deep to identify potential vulnerabilities and attack vectors.
- You exhibit great judgment and sharp technical instincts that allow you to differentiate essential versus nice-to-have and to make good choices about trade-offs.
- You have a point-of-view on the penetration testing methodology, tools, process, and what is appropriate for different stages of a scaling start-up.
- Hungry, humble, scrappy, and will thrive in fast-paced environments and manage multiple priorities simultaneously.
What You'll Do
Deliver Penetration Testing Engagements
- Conduct web, network, mobile and API penetration tests with automated and manual testing, using black box or gray box testing methods.
- Demonstrate lateral movement capabilities and expose potential data exfiltration opportunities to simulate real-world attack scenarios.
- Develop effective countermeasures to address both known and unknown vulnerabilities within internal networks, employing advanced adversarial tactics to highlight security gaps.
- Employ innovative thinking to overcome security protection mechanisms, craft proof-of-concept code, and exploit business logic.
- Present detailed reports and findings to customers in a clear and concise manner, in fluent written and oral English. Advise customers on remediation efforts as needed.
Build Penetration Testing Function
- Identify recurring issues and contribute to the automation of the penetration testing process, enabling scalability and expansion.
- Share your expertise through regular internal knowledge-sharing sessions, maintaining comprehensive documentation, and educating technical staff on security protocols.
- Serve as a trusted expert in the offensive security field, staying up-to-date with the latest trends and best practices.
- Collaborate cross-functionally with the Customer Success team and Sales & Marketing team to hit revenue goals and deliver the best customer experience.
Skillsets/ Requirements
- 3-5+ years in a pentesting / red teaming role.
- Deep technical expertise in network pentesting, web app pentesting, AWS pentesting, and API pentesting.
- Familiarity with the majority of the following areas: Android pentesting, iOS pentesting, cloud pentesting, OSINT, exploit development, IoT pentesting, Web3 security review, secure code review - white box pentesting.
- At least 1 of the following certifications: Burp Suite Certified Practitioner, OSCP OR PWPT.
- Knowledge of current attack methods, manual penetration testing techniques, and popular hacking tools (e.g., Nessus, Nmap, Kali Linux, Burp Suite Pro).
- Experience with Hack the Box, Portswigger Academy, or similar learning platforms.
- Proficient scripting skills in bash, Python, or similar languages.
- Fluency in English, with exceptional verbal & written communication. Youre able to convey complex, technical topics to an array of stakeholders in a digestible and compelling manner.
- Strong project management skills with experience working with cross-functional teams and influencing stakeholders at all levels of the organization.
Bonus Points
- Familiarity with programming languages such as C/C++, Java, .NET, Python, and manual source code analysis.
Compensation
: - Competitive base salary
- Exceptional private healthcare
- Early equity in a fast-growing company
- Work-from-home model
- Flexible PTO
- Home office equipment
- Monthly wellness and home Wi-Fi stipend