Penetration Tester @Sprocket Security
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2mths ago

[Hiring] Penetration Tester @Sprocket Security

2mths ago - Sprocket Security is hiring a remote Penetration Tester. πŸ’Έ Salary: unspecified πŸ“Location: Northern America

Role Description

As a Penetration Tester at Sprocket Security, your mission is to conduct continuous penetration testing across various attack surfaces, including:

  • Network
  • Web applications
  • Cloud
  • Social engineering

Your responsibilities include:

  • Owning continuous testing across clients' full attack surfaces by conducting manual penetration testing and directing automation.
  • Taking raw leads from the platform and pushing them into deep, business-level impact, including post-exploitation and privilege escalation.
  • Validating whether activity was detected and acted upon, and identifying where defenses held.
  • Writing clear, business-relevant attack narratives for technical and non-technical audiences.
  • Running debriefs and client conversations to build trust and position Sprocket as a partner.
  • Feeding repeatable techniques and automation candidates back to R&D.
  • Mentoring junior testers and interns, and fostering a collaborative team environment.
  • Building scripts and tooling to improve efficiency for yourself and the team.

Qualifications

  • Web application testing beyond OWASP Top 10 basics: auth flaws, business logic, injection at depth.
  • Network and Active Directory testing: lateral movement, privilege escalation.
  • Comfort directing, supervising, and validating AI and automation tooling.
  • Post-exploitation and impact demonstration with the ability to translate findings into business implications.
  • Scripting ability (Python, Bash, or equivalent) with a track record of building tools.
  • Client-facing experience delivering findings and handling conversations.
  • Genuine comfort with ambiguity and shifting responsibilities.
  • A collaborative approach: asking early, sharing often, and investing in others.

Requirements

  • OSCP or equivalent hands-on certification (preferred).
  • OSWE, CRTO, GPEN, GWAPT, or cloud security certifications (AWS Security Specialty, AZ-500) (preferred).
  • Published research, disclosed CVEs, or an active bug bounty profile (preferred).
  • No specific degree or certification required; equivalent hands-on experience is valued.
  • If OSCP or equivalent isn't held, it is expected within roughly 12 months, supported by a training budget.

Benefits

  • Unlimited and mandatory PTO for healthy work/life balance.
  • Company matched 401k (immediate eligibility).
  • 75% company contribution for health insurance for employees and 50% for dependents.
  • 100% company contribution for dental and vision.
  • Flexible working hours.
  • Hardware and tools of your choice.
  • Support for career development with paid training, conferences, certifications, etc.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Northern America
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Penetration Tester @Sprocket Security
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Northern America
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,895+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later