Netrio logo
Netrio
Posted 39 days agoVerified live 2d ago

Associate Penetration Tester

Brief overview

Remote
1+ yrsMinimum
Network Penetration TestingTCP/IP, DNS, SMB, LDAP, and HTTP/SWindowsActive DirectoryLinuxNmapNessusMetasploitImpacketBloodHoundResponderHashcatBurp SuitePythonPowerShellBashClient-Facing Communication

About the company

NETRIO is a Managed Services Provider supporting a wide variety of technology assets and services for small to medium sized organizations.

Job description

Summary

Netrio is a managed service provider specializing in IT solutions, cybersecurity, cloud, connectivity, voice, and custom application development. The Associate Penetration Tester performs internal and external network penetration tests, validates vulnerabilities, documents findings, conducts remediation retesting, and follows authorized engagement scopes and rules.

Responsibilities

  • Conduct external network penetration tests: attack surface enumeration, service and application discovery, credential attacks, and exploitation of exposed services within an approved scope
  • Conduct internal network penetration tests: network and host enumeration, Active Directory reconnaissance and attack path analysis, credential harvesting and reuse, privilege escalation, and lateral movement
  • Validate vulnerability scanner output and eliminate false positives through manual testing
  • Capture reproducible evidence for every finding
  • Perform remediation retesting
  • Operate strictly within the authorized scope and rules of engagement on every engagement

Skills

  • 1-3 years in IT, systems or network administration, SOC, or a related field, or demonstrable hands-on offensive security skill through labs and personal projects
  • Solid networking fundamentals: TCP/IP, DNS, SMB, LDAP, HTTP/S
  • Working knowledge of Windows and Active Directory, including common misconfigurations
  • Comfortable in a Linux terminal
  • Familiarity with standard tooling such as Nmap, Nessus, Metasploit, Impacket, BloodHound, Responder, Hashcat, and Burp Suite
  • Basic scripting in Python, PowerShell, or Bash
  • Strong written communication and a professional client-facing demeanor
  • OSCP, PNPT, CPTS, eJPT, or CRTP — held or in progress
  • Documented lab or CTF work you can discuss in detail
  • Prior systems or network administration experience
  • Exposure to cloud or web application testing

Qualifications

Must Haves

  • 1-3 years in IT, systems or network administration, SOC, or a related field, or demonstrable hands-on offensive security skill through labs and personal projects
  • Solid networking fundamentals: TCP/IP, DNS, SMB, LDAP, HTTP/S
  • Working knowledge of Windows and Active Directory, including common misconfigurations
  • Comfortable in a Linux terminal
  • Familiarity with standard tooling such as Nmap, Nessus, Metasploit, Impacket, BloodHound, Responder, Hashcat, and Burp Suite
  • Basic scripting in Python, PowerShell, or Bash
  • Strong written communication and a professional client-facing demeanor

Nice to Haves

  • OSCP, PNPT, CPTS, eJPT, or CRTP — held or in progress
  • Documented lab or CTF work you can discuss in detail
  • Prior systems or network administration experience
  • Exposure to cloud or web application testing

More jobs like this