Senior Penetration Tester
Do the work that actually finds what others miss. You will lead full-scope offensive engagements end to end, the senior who runs the engagement and owns the outcome, with no checklist to hide behind. This is a role where your judgment is the product.
What you’ll do
- Lead engagements yourself: web and API, internal and external network, cloud, and where it fits, mobile
- Go past the scanner: exploit business-logic flaws, chain low-severity issues into real attack paths, and prove impact
- Write reports a CISO and an engineer can both act on, with proof-of-concept evidence and honest severity
- Use our in-house AI tooling (Argus) to cover ground faster, so your hours go to the work only a human can do
- Help shape how we test, and mentor as we grow, without the firm ever becoming a body shop
What you’ll bring
- Several years of hands-on offensive security, with real manual depth, not just running tools
- Genuine skill with authorization flaws, business logic, and chaining, the findings scanners miss
- Certifications like OSCP, OSCE, or OSEP are welcome; demonstrated ability matters more
- Bonus depth in IoT, embedded, hardware, or AI and LLM security, areas we go where most firms cannot
- A clear writer who can make a finding land for executives and engineers alike
What we offer
- You lead the engagements you are on, with support when useful and no corners cut
- Real variety and depth, not the same scoped scan on repeat
- AI that amplifies your work instead of replacing your judgment
- Autonomy and direct work with the founder; your name is on the engagement, not a cover page