Sprocket Security logo
Sprocket Security
Posted 66 days agoVerified live 2d ago

Penetration Tester

Brief overview

Remote
Penetration TestingWeb Application Penetration TestingVulnerability Identification and ExploitationWindows SystemsLinux SystemsCloud SystemsRuby ProgrammingPython ProgrammingBash ScriptingBurp Suite ProNessusMetasploitCobaltStrikeAWSAzureTerraformAnsible

About the company

Sprocket Security logo
Sprocket Securitysprocketsecurity.com

Sprocket Security provides continuous security testing services.

Job description

Summary

Sprocket Security is dedicated to helping secure companies through penetration testing. The Penetration Tester will simulate real-world cyber-attack tactics to identify security vulnerabilities and contribute to continuous testing efforts.

Responsibilities

  • Perform web application testing across a large and diverse client base using established methodologies, and creating your own
  • Perform network and wireless testing methodologies at scale from time to time
  • Discover newly exploitable systems across our fleet of clients. It's fun to test that new vulnerability the day it's released!
  • Build payloads and C2 infrastructure that evades defenses
  • Mimic tactics and techniques used by real-world adversaries
  • Show impact with post-exploitation activities
  • Manage our platform by conducting tasks, write findings, and work with clients to help detect and prevent
  • Build scripts, tooling, or templates to improve personal testing efficiency and contribute ideas for future automation in the platform. You'll commonly program in the following languages: Ruby, Python, PowerShell, C# Bash, etc
  • Advanced usage of the following tools: Burp Suite Pro, Nessus, Metasploit, CobaltStrike, etc
  • Manage project lifecycles and present professionally to clients. Kickoff calls, debriefs, etc
  • Work closely with development teams to migrate human-driven tasks into automation
  • Work with AWS, Azure, terraform, ansible, and gitlab pipelines

Skills

  • Three or more years of hands-on penetration testing experience
  • One or more years of hands-on web application penetration testing experience
  • Detailed knowledge of identifying and exploiting vulnerabilities in Windows, Linux, and cloud -based systems
  • Programming experience in Ruby, Python, Bash. Bonus (C#, JavaScript, terraform, ansible)
  • One publicly available contribution to the security community? (e.g., open-source tool or code on GitHub, published blog posts, conference talk, podcast, research paper etc etc)
  • Clear and concise verbal and written skills
  • United States resident
  • OSCP or equivalent skills-based certification mandatory, or will need to obtain within 12 months of employment
  • Adversary Simulation experience
  • Has industry involvement by contributes research, open-source projects, or public speaking
  • Experience managing or working with management on security projects and teams. Bonus if CISSP certified
  • Remote work acceptable
  • Preferred proximity to Madison, WI

Qualifications

Must Haves

  • Three or more years of hands-on penetration testing experience
  • One or more years of hands-on web application penetration testing experience
  • Detailed knowledge of identifying and exploiting vulnerabilities in Windows, Linux, and cloud -based systems
  • Programming experience in Ruby, Python, Bash. Bonus (C#, JavaScript, terraform, ansible)
  • One publicly available contribution to the security community? (e.g., open-source tool or code on GitHub, published blog posts, conference talk, podcast, research paper etc etc)
  • Clear and concise verbal and written skills
  • United States resident

Nice to Haves

  • OSCP or equivalent skills-based certification mandatory, or will need to obtain within 12 months of employment
  • Adversary Simulation experience
  • Has industry involvement by contributes research, open-source projects, or public speaking
  • Experience managing or working with management on security projects and teams. Bonus if CISSP certified
  • Remote work acceptable
  • Preferred proximity to Madison, WI

Benefits

  • Unlimited and mandatory PTO for healthy work/life balance
  • Company matched 401k (immediate eligibility, no one should have to wait to start saving)
  • 75% company contribution for health insurance for employees
  • 50% for dependants health insurance contribution
  • 100% company contribution for dental and vision
  • Flexible working hours
  • Hardware and tools of your choice
  • Support for your career development with paid training, conferences, certifications, etc.

More jobs like this