Jobedly Post a Job

Penetration Tester

Bishop Fox · Remote
RemoteFull-timeConsulting PracticeMarketing & Media$102,000–$138,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Penetration Tester role

Penetration Tester positions focus on delivering results in their domain. This page aggregates open Penetration Tester roles and what employers typically expect.

At Bishop Fox, security isn't just a job - it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation. Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions - including 16 open-source tools and 50 security advisories published in the past five years - we're committed to making the digital world safer. Given our exceptional growth, we are expanding and hiring a Pen Tester to join us on this exciting journey. We’re looking for a talented, experienced professional hacker to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US and internationally-based teams supporting clients across multiple industries. Who Are You and What You’ll Do You’re a cybersecurity consultant with a strong offensive security mindset and a passion for understanding how modern applications, cloud platforms, APIs, and emerging technologies operate at a deep technical level. You enjoy uncovering security weaknesses, thinking creatively about attack paths, and helping organizations solve complex security challenges through practical, risk-focused assessments. At Bishop Fox, you’ll work on a wide variety of security engagements including Cloud Security Assessments, Mobile Application Security Testing, Hybrid Application Assessments (HAA), and AI/LLM Security Assessments. You’ll evaluate modern applications and distributed systems across cloud-native, mobile, backend, and AI-enabled environments. Your responsibilities will include performing hands-on security testing, analyzing application behavior, reviewing source code, identifying realistic exploitation scenarios, and validating security controls across modern architectures. You’ll work closely with clients and internal teams to deliver high-quality technical assessments and actionable remediation guidance. As a consultant, you’ll contribute throughout the full engagement lifecycle from scoping and test planning to execution, reporting, and client presentations. Success in this role requires strong technical depth, structured testing methodologies, effective communication skills, and the ability to adapt quickly to new technologies and environments. Your Experience 4+ years of experience in application security assessments, penetration testing, or offensive security engagements Strong understanding of application security fundamentals, modern attack techniques, and common vulnerabilities affecting web applications, APIs, mobile applications, and cloud-native environments Hands-on experience testing REST APIs, including authentication/authorization flaws, IDORs, injection vulnerabilities, session management issues, and business logic flaws Strength with AWS services and cloud security concepts, including IAM, STS, S3, Lambda, API Gateway, CloudTrail, CloudWatch, and secure communication patterns such as SigV4 Solid understanding of networking and web fundamentals, including HTTP/HTTPS, TCP/IP, DNS, API communication flows, cookies, headers, and related concepts Experience reviewing source code for security issues in Java, C#, and Python applications Knowledge of secure coding principles and common risks such as SSRF, insecure deserialization, injection vulnerabilities, sensitive data exposure, and insecure cloud integrations Understanding of SDLC, CI/CD pipelines, and secure development practices Experience using security assessment and code review tools such as Burp Suite, Semgrep, Git, AWS CLI, and API testing/debugg…

Salary estimate

$102,000 – $138,000/yr
Provided by the employer.

Skills for this role

PythonJAVAC#RESTAWSCi/CdGITLLMCommunicationSecurityPenetration Testing

Resume tips for Penetration Tester applicants

Interview preparation

Prepare concrete STAR-format stories that show Penetration Tester outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Penetration Tester problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Bishop Fox

Bishop Fox is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles