Offensive Security

Penetration Tester

Location Remote Department Offensive Security Reports to Head of Security Operations

As a Penetration Tester at CyberBlade, you are a crucial part of our offensive security team, tasked with assessing and fortifying the security posture of our clients. You lead hands-on engagements across networks, applications and cloud, then turn what you find into clear, actionable remediation.

Key Responsibilities

What you will do

Penetration Testing and Exploitation

Lead penetration tests across networks, web applications, mobile apps and cloud environments, identifying and exploiting vulnerabilities.

Red Teaming and Simulated Attacks

Conduct red team exercises that simulate real-world attacks, focusing on advanced tactics like lateral movement and data exfiltration.

Vulnerability Assessment and Reporting

Use both automated tools and manual techniques to identify vulnerabilities, then document and present findings with actionable remediation steps to clients.

Social Engineering

Design and execute phishing, vishing and other social engineering campaigns to assess human security vulnerabilities.

Client Interaction and Debriefing

Communicate risks and provide practical solutions to clients in clear, non-technical terms.

Collaboration and Continuous Learning

Work closely with other security teams and stay current on the latest threats, tools and techniques. Share knowledge within the team to raise the bar for everyone.

Required Qualifications

What we are looking for

  • Hands-on penetration testing experience. Proven experience performing penetration testing across network, web application, cloud and mobile platforms.
  • Strong technical knowledge. Deep understanding of network protocols (TCP/IP, DNS, HTTP), web application security (OWASP Top 10) and operating systems (Linux, Windows, macOS).
  • Exploitation techniques. Familiarity with common frameworks such as Metasploit and Cobalt Strike, and manual techniques to compromise systems and escalate privileges.
  • Tooling expertise. Proficiency with Burp Suite, Nmap, Wireshark, Kali Linux, Hydra, Nikto, Aircrack-ng and other security testing tools.
  • Cloud security experience. Familiarity with AWS, Azure and Google Cloud and the attack surfaces unique to cloud environments.
  • Scripting and automation. Comfortable writing custom scripts in Python, Bash or PowerShell to automate tasks, exploit vulnerabilities or build tooling.
  • Strong report writing. Ability to document findings clearly and professionally, with actionable remediation advice for clients.
  • Problem-solving. Ability to think critically and creatively, simulating real-world attacks and finding new avenues for exploitation.
  • Certifications (preferred). CRTP, CRTE, CRTO, PNPT, eWPTX, eCPTX or similar. Red teaming and advanced penetration testing experience is a plus.
Ready when you are

Let's put your defenses to the test.

Whether you are a CEO or an individual in a home office, we keep pricing fair and stay in your corner long after the engagement ends. Tell us what you are protecting.