Summary
Netrio is a managed service provider specializing in IT solutions, cybersecurity, cloud, connectivity, voice, and custom application development. The Associate Penetration Tester performs internal and external network penetration tests, validates vulnerabilities, documents findings, conducts remediation retesting, and follows authorized engagement scopes and rules.
Responsibilities
- Conduct external network penetration tests: attack surface enumeration, service and application discovery, credential attacks, and exploitation of exposed services within an approved scope
- Conduct internal network penetration tests: network and host enumeration, Active Directory reconnaissance and attack path analysis, credential harvesting and reuse, privilege escalation, and lateral movement
- Validate vulnerability scanner output and eliminate false positives through manual testing
- Capture reproducible evidence for every finding
- Perform remediation retesting
- Operate strictly within the authorized scope and rules of engagement on every engagement
Skills
- 1-3 years in IT, systems or network administration, SOC, or a related field, or demonstrable hands-on offensive security skill through labs and personal projects
- Solid networking fundamentals: TCP/IP, DNS, SMB, LDAP, HTTP/S
- Working knowledge of Windows and Active Directory, including common misconfigurations
- Comfortable in a Linux terminal
- Familiarity with standard tooling such as Nmap, Nessus, Metasploit, Impacket, BloodHound, Responder, Hashcat, and Burp Suite
- Basic scripting in Python, PowerShell, or Bash
- Strong written communication and a professional client-facing demeanor
- OSCP, PNPT, CPTS, eJPT, or CRTP — held or in progress
- Documented lab or CTF work you can discuss in detail
- Prior systems or network administration experience
- Exposure to cloud or web application testing
Qualifications
Must Haves
- 1-3 years in IT, systems or network administration, SOC, or a related field, or demonstrable hands-on offensive security skill through labs and personal projects
- Solid networking fundamentals: TCP/IP, DNS, SMB, LDAP, HTTP/S
- Working knowledge of Windows and Active Directory, including common misconfigurations
- Comfortable in a Linux terminal
- Familiarity with standard tooling such as Nmap, Nessus, Metasploit, Impacket, BloodHound, Responder, Hashcat, and Burp Suite
- Basic scripting in Python, PowerShell, or Bash
- Strong written communication and a professional client-facing demeanor
Nice to Haves
- OSCP, PNPT, CPTS, eJPT, or CRTP — held or in progress
- Documented lab or CTF work you can discuss in detail
- Prior systems or network administration experience
- Exposure to cloud or web application testing