Bishop Fox logo
Bishop Fox
Posted 66 days agoVerified live 1d ago

Penetration Tester

Brief overview

Remote
Application Security AssessmentsPenetration TestingOffensive SecurityWeb Application SecurityAPI SecurityMobile Application SecurityCloud SecurityAWS IAMAWS STSAWS S3AWS LambdaAWS API GatewayAWS CloudTrailAWS CloudWatchSigV4HTTP/HTTPSTCP/IP

About the company

Bishop Fox logo
Bishop Foxbishopfox.com

Bishop Fox delivers offensive security solutions to protect dynamic attack surfaces.

Job description

Summary

Bishop Fox is a leader in continuous offensive security and penetration testing, dedicated to safeguarding digital landscapes for a wide range of clients. They are seeking a talented Penetration Tester to perform hands-on security testing, analyze application behavior, and deliver high-quality technical assessments to secure complex software and technologies.

Responsibilities

  • Performing hands-on security testing
  • Analyzing application behavior
  • Reviewing source code
  • Identifying realistic exploitation scenarios
  • Validating security controls across modern architectures
  • Working closely with clients and internal teams to deliver high-quality technical assessments and actionable remediation guidance
  • Contributing throughout the full engagement lifecycle from scoping and test planning to execution, reporting, and client presentations

Skills

  • 4+ years of experience in application security assessments, penetration testing, or offensive security engagements
  • Strong understanding of application security fundamentals, modern attack techniques, and common vulnerabilities affecting web applications, APIs, mobile applications, and cloud-native environments
  • Hands-on experience testing REST APIs, including authentication/authorization flaws, IDORs, injection vulnerabilities, session management issues, and business logic flaws
  • Strength with AWS services and cloud security concepts, including IAM, STS, S3, Lambda, API Gateway, CloudTrail, CloudWatch, and secure communication patterns such as SigV4
  • Solid understanding of networking and web fundamentals, including HTTP/HTTPS, TCP/IP, DNS, API communication flows, cookies, headers, and related concepts
  • Experience reviewing source code for security issues in Java, C#, and Python applications
  • Knowledge of secure coding principles and common risks such as SSRF, insecure deserialization, injection vulnerabilities, sensitive data exposure, and insecure cloud integrations
  • Understanding of SDLC, CI/CD pipelines, and secure development practices
  • Experience using security assessment and code review tools such as Burp Suite, Semgrep, Git, AWS CLI, and API testing/debugging tools
  • Comfortable working across Linux, Windows, and macOS environments
  • Experience or strong interest in AI/LLM security, including prompt injection, RAG risks, insecure integrations, excessive permissions, and the OWASP Top 10 for LLM Applications
  • Strong written and verbal communication skills, with the ability to deliver clear, actionable findings and communicate technical risks to both technical and executive stakeholders
  • Experience following structured testing methodologies, documentation standards, and validation/retesting workflows
  • Strong collaboration and interpersonal skills when working with security, engineering, and client teams
  • Ability to manage multiple concurrent engagements while maintaining high-quality deliverables and attention to detail
  • Curious, adaptable, and professional mindset with a passion for continuous learning and emerging security trends
  • Exposure to hardware or embedded device security testing
  • Familiarity with cloud-native and serverless architectures
  • Consulting or client-facing experience
  • Relevant security certifications or hands-on research contributions

Qualifications

Must Haves

  • 4+ years of experience in application security assessments, penetration testing, or offensive security engagements
  • Strong understanding of application security fundamentals, modern attack techniques, and common vulnerabilities affecting web applications, APIs, mobile applications, and cloud-native environments
  • Hands-on experience testing REST APIs, including authentication/authorization flaws, IDORs, injection vulnerabilities, session management issues, and business logic flaws
  • Strength with AWS services and cloud security concepts, including IAM, STS, S3, Lambda, API Gateway, CloudTrail, CloudWatch, and secure communication patterns such as SigV4
  • Solid understanding of networking and web fundamentals, including HTTP/HTTPS, TCP/IP, DNS, API communication flows, cookies, headers, and related concepts
  • Experience reviewing source code for security issues in Java, C#, and Python applications
  • Knowledge of secure coding principles and common risks such as SSRF, insecure deserialization, injection vulnerabilities, sensitive data exposure, and insecure cloud integrations
  • Understanding of SDLC, CI/CD pipelines, and secure development practices
  • Experience using security assessment and code review tools such as Burp Suite, Semgrep, Git, AWS CLI, and API testing/debugging tools
  • Comfortable working across Linux, Windows, and macOS environments
  • Experience or strong interest in AI/LLM security, including prompt injection, RAG risks, insecure integrations, excessive permissions, and the OWASP Top 10 for LLM Applications
  • Strong written and verbal communication skills, with the ability to deliver clear, actionable findings and communicate technical risks to both technical and executive stakeholders
  • Experience following structured testing methodologies, documentation standards, and validation/retesting workflows
  • Strong collaboration and interpersonal skills when working with security, engineering, and client teams
  • Ability to manage multiple concurrent engagements while maintaining high-quality deliverables and attention to detail
  • Curious, adaptable, and professional mindset with a passion for continuous learning and emerging security trends

Nice to Haves

  • Exposure to hardware or embedded device security testing
  • Familiarity with cloud-native and serverless architectures
  • Consulting or client-facing experience
  • Relevant security certifications or hands-on research contributions

Benefits

  • Generous Time Off and Company-Wide Holidays
  • Team Events and International Travel Opportunities
  • Work From Home Support
  • Training Budget
  • Saving Fund
  • Food Coupons
  • Health and Wellbeing programs

More jobs like this