Penetration Tester / Ethical Hacker
The job description
Tech stack. Kali Linux, Burp Suite, Metasploit, Cobalt Strike or similar C2, BloodHound and Active Directory tooling, Nmap, Python and PowerShell, structured report writing
About the role
You will think like an attacker against a technology company's own products and infrastructure, then hand defenders the exact blueprint needed to stop you. The offensive security team runs network, web application, cloud, and social engineering engagements year-round against production systems. You will scope engagements, execute them creatively, and deliver findings that change how the company builds. This role matters because the findings you produce become the prioritized fixes that measurably shrink the company's real attack surface, and your creativity determines whether testing uncovers the flaws that genuinely matter. You will also mentor junior testers on methodology, tradecraft, and report writing as the team grows.
What you will achieve
- Deliver full-scope penetration tests each quarter covering external, internal, web application, and cloud attack paths, with chained exploit narratives showing real business impact.
- Chain individually low-severity findings into high-impact attack stories that executives understand clearly and fund fixes for.
- Achieve domain compromise in assumed-breach exercises and document every detection gap discovered for the blue team to close.
- Write reports achieving 90 percent remediation of critical and high findings within SLA, tracked through to verified closure.
- Build reusable tooling, payloads, and infrastructure that cut engagement setup time in half for the entire team.
What you will bring
Must-haves
- 2 to 5 years in penetration testing, red teaming, or offensive security consulting with direct client-facing delivery.
- Strong Active Directory attack and defense knowledge: Kerberoasting, delegation abuse, and BloodHound-driven path analysis.
- Web application testing skills with Burp Suite, including authentication flaws, access control issues, and injection classes.
- Cloud penetration testing fundamentals across AWS, Azure, or GCP identity and misconfiguration attack paths.
- Clear, persuasive report writing focused on demonstrable business impact rather than lists of CVE identifiers.
- Discipline to remain strictly within agreed scope and to handle sensitive access with complete professionalism.
- Creativity under constraints: you find novel paths when the obvious ones are blocked.
Nice-to-haves
- OSCP, GPEN, or GXPN certification.
- Experience with adversary emulation frameworks such as MITRE CALDERA.
- Published CTF writeups, open-source offensive tools, or conference talks.
- Familiarity with social engineering assessment methods and pretexting tradecraft.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta