Back to the stack

SENIOR PENETRATION TESTER (Remote)

Remote Worldwide Hiring now

Emagine IT has an immediate need for a Sr. Penetration Tester to join our team in support of our Commercial Services Team located remote. In this role, you will facilitate Penetration Tests, Threat Hunting exercises and possibly other advanced-level Continuous Monitoring Activities within cloud-based environments. To succeed in this position, you will need a strong understanding of security-related system controls and an understanding of the various testing methods utilized to ascertain the effectiveness of those controls. You will work in a team atmosphere with an experienced Sr. Consultant Project Lead, and you will be assigned technical sections and provide client-ready deliverables. In this role, you will:

  • Execute testing procedures in accordance with NIST SP 800-53A and industry testing standards like OWASP, MITRE, etc.
  • Test for vulnerabilities, validate exploitable vulnerabilities within network, cloud, web and mobile environments
  • Perform Social Engineering campaigns, including email phishing, spear phishing, phone pre-text calling – Including but not limited to creation of landing pages, creation of embedded executable payloads
  • Develop Rules of Engagement, Penetration Test Plans, Penetration Testing report, Power Point presentations for kick-off and closing of client engagements
  • Author recommendations based on findings to improve security postures compliant with NIST controls
  • Penetration Testing/Threat Hunting (75%); Advisory/Consulting (%25)
  • Experience using:
  • Kali Linux
  • Cobalt Strike
  • Social Engineering Toolkit
  • Burp Suite
  • Nessus
  • Metasploit Framework.
  • Experience using the MITRE ATT&CK Framework
  • Good understanding of coding (Python, Ruby, etc.)
  • Understanding of SQL commands and testing
  • Expected Travel less than 25% Essential Functions / Duties & Responsibilities 1. Develop Testing Guides Based on Methodologies (MITRE, OWASP, etc.)
  • Creation of Comprehensive Testing Frameworks: Develop detailed penetration testing guides and frameworks that align with industry standards such as MITRE ATT&CK, OWASP Top Ten, NIST, and others. These guides serve as a foundation for the team, providing step-by-step methodologies for various types of tests, such as web application, network, mobile, wireless, and social engineering assessments.
  • Incorporation of Advanced Techniques: Regularly update these guides to incorporate the latest attack techniques and defensive strategies. This includes adapting to emerging threats and ensuring the guides remain relevant in the rapidly evolving cybersecurity landscape.
  • Customization for Client Environments: Tailor these methodologies to meet specific client environments and industry requirements, ensuring that the testing approach is both comprehensive and contextually appropriate. 2. Develop Team Trainings Based on Test Guides and Engagement Debriefs
  • Training Program Development: Design and implement training programs for the penetration testing team, leveraging the developed test guides. This includes foundational training for new hires and advanced sessions for experienced testers, covering both the theoretical and practical aspects of penetration testing.
  • Debrief and Knowledge Sharing: Conduct debrief sessions following each engagement to discuss unique or novel findings. These sessions aim to share lessons learned, explore new vulnerabilities or attack techniques encountered, and foster a culture of continuous learning within the team.
  • Simulation and Hands-On Training: Organize practical, hands-on workshops and simulations to provide team members with real-world experience in using new tools and methodologies. Encourage a red teaming mindset to challenge the status quo and think like adversaries. 3. Take on QA Responsibilities for Reports or Rules of Engagement (ROEs)
  • Quality Assurance for Reports: Perform thorough quality assurance (QA) reviews of penetration testing reports to ensure accuracy, clarity, and completeness. This includes verifying that findings are well-documented, evidence is clearly presented, and recommendations are actionable and relevant.
  • Consistency and Compliance: Ensure that all reports adhere to internal and external compliance requirements and follow a standardized format. This includes checking that language is professional, findings are ranked by risk severity, and there are no spelling or grammatical errors.
  • Rules of Engagement (ROE) Review: Review and refine Rules of Engagement (ROE) documents to ensure they are clear, comprehensive, and aligned with client expectations and legal considerations. This involves outlining the scope, limitations, and specific rules under which testing will occur, and mitigating any potential risks. 4. More Active Role in Blog Posting and Research
  • Thought Leadership and Content Creation: Take a proactive role in writing blog posts and research papers that contribute to the broader cybersecurity community. This includes sharing insights from recent engagements, discussing

Apply tot his job Apply To this Job

Apply for this role Opens the employer's application page — free, no JobStack account needed.

More from the stack

Sr. People Operations Specialist, Clinical Ops & Compliance

Remote Worldwide
View role

Truck Driver - Local Class A - $10K Retention Bonus - Penske Logistics

Remote Worldwide
View role

Truck Drivers - CDL Class A and B - Nationwide

Remote Worldwide
View role

Global Benefits Consultant

Remote Worldwide
View role

HR and People Operations Analyst

Remote Worldwide
View role

Senior Manager of Total Rewards & People Operations

Remote Worldwide
View role

Growth Marketing Manager (Remote)

Remote Worldwide
View role

Digital Performance Marketing Manager

Remote Worldwide
View role

Fleet Technician 2 (Experienced)(Rotating Shifts)

Remote Worldwide
View role

Manager, PVRM

Remote Worldwide
View role

Associate Director, Financial Services

Remote Worldwide
View role

Experienced Data Entry Specialist for Remote Work with Flexible Schedule - blithequark

Remote Worldwide
View role

Exciting Remote Career Opportunities with Amazo...

Remote Worldwide
View role

Immediately Need ABA Behavior Therapist / Behavior Technician ? Northeastern in USA

Remote Worldwide
View role

Accounts Payable Representative

Remote Worldwide
View role

[Remote] Sales Representative

Remote Worldwide
View role

Disney is hiring: Social Media Manager – TV & Titles (National Geographic) in Wa

Remote Worldwide
View role

Head of GIS for TraceAir – a US-based site work intelligence software that empowers construction teams with critical data at their fingertips

Remote Worldwide
View role

Experienced Remote Customer Engagement Associate – Summer Jobs Virtual Opportunity at arenaflex

Remote Worldwide
View role

Researcher - CHRR

Remote Worldwide
View role