We are looking for a Mid Penetration Tester to deliver penetration tests to Thoropass customers, including vulnerability assessments, web app pentests, network pentests, and API pentests.  
  This role will be a player-coach, responsible for delivering our first batch of customer-facing pentest reports. As we scale the offering, this role will also mentor junior resources to deliver consistently high-quality pentests. The ideal candidate will be equal-parts penetration tester, strategic thinker, and operational doer with a passion for solving complex challenges and delivering measurable impact for our company and customers. 
      
   
About You
   -  You adopt the mindset of an attacker, delving deep to identify potential vulnerabilities and attack vectors. 
-  You exhibit great judgment and sharp technical instincts that allow you to differentiate essential versus nice-to-have and to make good choices about trade-offs. 
-  You have a point-of-view on the penetration testing methodology, tools, process, and what is appropriate for different stages of a scaling start-up. 
-  Hungry, humble, scrappy, and will thrive in fast-paced environments and manage multiple priorities simultaneously. 
 
What You'll Do
   
     
Deliver Penetration Testing Engagements
   -  Conduct web, network, mobile and API penetration tests with automated and manual testing, using black box or gray box testing methods. 
-  Demonstrate lateral movement capabilities and expose potential data exfiltration opportunities to simulate real-world attack scenarios. 
-  Develop effective countermeasures to address both known and unknown vulnerabilities within internal networks, employing advanced adversarial tactics to highlight security gaps. 
-  Employ innovative thinking to overcome security protection mechanisms, craft proof-of-concept code, and exploit business logic. 
-  Present detailed reports and findings to customers in a clear and concise manner, in fluent written and oral English. Advise customers on remediation efforts as needed. 
 
Build Penetration Testing Function
   -  Identify recurring issues and contribute to the automation of the penetration testing process, enabling scalability and expansion. 
-  Share your expertise through regular internal knowledge-sharing sessions, maintaining comprehensive documentation, and educating technical staff on security protocols. 
-  Serve as a trusted expert in the offensive security field, staying up-to-date with the latest trends and best practices. 
-  Collaborate cross-functionally with the Customer Success team and Sales & Marketing team to hit revenue goals and deliver the best customer experience. 
 
Skillsets/ Requirements
   -  3-5+ years in a pentesting / red teaming role. 
-  Deep technical expertise in network pentesting, web app pentesting, AWS pentesting, and API pentesting. 
-  Familiarity with the majority of the following areas: Android pentesting, iOS pentesting, cloud pentesting, OSINT, exploit development, IoT pentesting, Web3 security review, secure code review - white box pentesting. 
-  At least 1 of the following certifications: Burp Suite Certified Practitioner, OSCP OR PWPT.  
-  Knowledge of current attack methods, manual penetration testing techniques, and popular hacking tools (e.g., Nessus, Nmap, Kali Linux, Burp Suite Pro). 
 -  Experience with Hack the Box, Portswigger Academy, or similar learning platforms. 
-  Proficient scripting skills in bash, Python, or similar languages. 
-  Fluency in English, with exceptional verbal & written communication. Youre able to convey complex, technical topics to an array of stakeholders in a digestible and compelling manner.  
-  Strong project management skills with experience working with cross-functional teams and influencing stakeholders at all levels of the organization. 
 
Bonus Points
   -  Familiarity with programming languages such as C/C++, Java, .NET, Python, and manual source code analysis. 
 
Compensation
 :    -  Competitive base salary 
-  Exceptional private healthcare 
-  Early equity in a fast-growing company 
-  Work-from-home model 
-  Flexible PTO 
-  Home office equipment 
-  Monthly wellness and home Wi-Fi stipend