Summary
FRSecure is an information security company focused on helping clients, communities, and employees better protect themselves against risk. The Associate Penetration Tester validates client security postures through external, internal, application, and social engineering penetration tests, identifies vulnerabilities, documents findings, and advises on remediation.
Responsibilities
- Execute external penetration tests of client networks which includes reconnaissance, enumerate internet-facing client systems/services, identify vulnerabilities/misconfigurations, create reports based on findings, and deliver reports to clients
- Conduct internal penetration tests of client networks by enumerating client networks, identifying vulnerabilities/misconfigurations, creating reports based on findings, and delivering reports to clients
- Perform application penetration tests of client applications through reconnaissance, enumerating internet-facing client application, identifying vulnerabilities/misconfigurations, creating reports based on findings, and delivering reports to clients
- Execute social engineering tests which includes performing reconnaissance, designing campaign pretext, creating phishing emails, creating spoofed logon forms, creating reports based on findings, and delivering reports to clients
- Lead vulnerability assessments and remediation consulting by performing vulnerability scans, generating reports for scans, and advising on how to remediate vulnerability findings
- Document testing methodologies, technical findings, proof-of-concept evidence, attack chains, and business impact in clear, professional reports tailored to both technical and executive audiences
- Stay current on emerging threats, attack techniques, tools, and industry trends through independent research, training, certifications, lab work, and participation in knowledge-sharing initiatives
- Maintain compliance with internal quality standards, client confidentiality requirements, and applicable industry frameworks and testing methodologies, including OWASP, PTES, NIST, and MITRE ATT&CK
- Review colleague’s reports for formatting and narrative errors; provide feedback on fixes
Skills
- Only candidates located in the United States will be considered
- This is a full-time position worked Monday-Friday each week, with the expectation that the responsibilities can be completed in 40 hours each week
- Employees will need to work outside of these hours periodically to accommodate time zones of clients within the United States
- There is minimal travel associated with this position, less than 5%
- Associates degree in related field required, or equivalent combination of education, certification and experience
- Minimum of 1-2 years of experience managing IT systems in a professional environment required
- General knowledge of Networks, Linux systems, Windows systems, web applications, and scripting languages
- Familiarity of common attack tools, concepts, and frameworks used for reconnaissance, enumeration, vulnerability identification, exploitation, and reporting
- Excellent verbal and written communication skills, with the ability to clearly document technical findings, develop client-ready deliverables, and present complex information in a professional manner
- Demonstrated commitment to delivering exceptional customer service through professionalism, responsiveness, and effective management of client relationships throughout assessment engagements
- Ability to translate highly technical security concepts, risks, and remediation recommendations into clear, actionable guidance for business stakeholders and non-technical audiences
- Strong analytical and critical-thinking skills, with the ability to evaluate security weaknesses, validate findings, and recommend practical risk mitigation strategies
- Effective organizational and time management skills with the ability to manage multiple projects, prioritize competing deadlines, and maintain attention to detail in a fast-paced consulting environment
- Proficient with all Microsoft Office Suite products
- CEH, Net+ or similar IT or security industry recognized certification preferred
Qualifications
Must Haves
- Only candidates located in the United States will be considered
- This is a full-time position worked Monday-Friday each week, with the expectation that the responsibilities can be completed in 40 hours each week
- employees will need to work outside of these hours periodically to accommodate time zones of clients within the United States
- There is minimal travel associated with this position, less than 5%
- Associates degree in related field required, or equivalent combination of education, certification and experience
- Minimum of 1-2 years of experience managing IT systems in a professional environment required
- General knowledge of Networks, Linux systems, Windows systems, web applications, and scripting languages
- Familiarity of common attack tools, concepts, and frameworks used for reconnaissance, enumeration, vulnerability identification, exploitation, and reporting
- Excellent verbal and written communication skills, with the ability to clearly document technical findings, develop client-ready deliverables, and present complex information in a professional manner
- Demonstrated commitment to delivering exceptional customer service through professionalism, responsiveness, and effective management of client relationships throughout assessment engagements
- Ability to translate highly technical security concepts, risks, and remediation recommendations into clear, actionable guidance for business stakeholders and non-technical audiences
- Strong analytical and critical-thinking skills, with the ability to evaluate security weaknesses, validate findings, and recommend practical risk mitigation strategies
- Effective organizational and time management skills with the ability to manage multiple projects, prioritize competing deadlines, and maintain attention to detail in a fast-paced consulting environment
- Proficient with all Microsoft Office Suite products
Nice to Haves
- CEH, Net+ or similar IT or security industry recognized certification preferred
Benefits
- Flexible schedules and remote or hybrid work options.
- Opportunities to contribute in a collaborative, values-driven environment.
- Access to an Employee Assistance Program (EAP) and a culture that actively promotes mental wellbeing, open communication, and sustainable work practices.
- Ongoing learning opportunities and support for professional development.
- Medical, dental and vision insurance.
- Health savings, flexible savings and dependent care savings account options.
- Life and disability insurance.
- 401(k) with employer match up to 4%.
- Pet insurance.
- Unlimited paid time off.
- Paid parental leave: 6 weeks of 100% regular, straight time weekly pay for non-birthing parents, and 12 weeks of 100% regular, straight time weekly pay for birthing parents.
- 11 paid holidays.
- Volunteer time off.