×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior IT Penetration Tester

Job in Oak Brook, DuPage County, Illinois, 60523, USA
Listing for: BDO USA, LLP
Full Time position
Listed on 2026-09-25
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below

Job Summary:

The Senior Cyber Security Penetration Tester performs offensive security testing for BDO clients and provides practical, risk-based remediation guidance. This role works with client stakeholders to define scope, rules of engagement, and objectives, executes testing to simulate realistic attacker behaviors, and communicates results clearly to both technical and executive audiences. Engagements may include external and internal network penetration testing, Active Directory attack path testing, web and API application testing, cloud and Microsoft 365 security assessments, and AI enabled application testing.

The role may also support red team and purple team exercises in collaboration with client SOC teams and contributes to internal tooling and automation through shared repositories.

Job Duties:
  • Participates in client penetration testing and vulnerability assessment engagements across external and internal networks, Active Directory, web applications, APIs, cloud platforms, and Microsoft 365, including reconnaissance, attack surface discovery, and service enumeration
  • Uses offensive security tools and techniques to identify, validate, and demonstrate exploitability, including Kali Linux toolchain, Nessus/Tenable, Nmap, Burp Suite, Metasploit, and Blood Hound, and validates exploitability end to end for High and Critical findings and when feasible for other findings
  • Performs authenticated testing when appropriate by coordinating access approvals, applying least privilege, safeguarding secrets, and confirming access removal or rotation at engagement closeout
  • Performs and reviews web and API security testing using Burp Suite and related techniques, focusing on authentication, session management, access control, injection, insecure deserialization, and business logic, and documents reproducible steps and payloads for remediation and retesting
  • Reviews AI-enabled applications and LLM integrations for common risks (for example, prompt injection, sensitive data exposure, insecure output handling, and tool or function calling abuse) and provides practical mitigation guidance aligned to OWASP Top 10 for LLM Applications
  • Supports scoping and delivery under the direction of an assigned Project Manager by documenting objectives and rules of engagement, coordinating technical logistics with client teams, providing timely status updates across concurrent engagements, and ensuring testing is performed safely within approved scope
  • For internal and Active Directory engagements, maps and demonstrates feasible attack paths, for example, using Blood Hound or equivalent, including privilege escalation and lateral movement, validates root causes in configuration and permissions, and provides actionable remediation
  • Documents reproducible work papers and evidence with appropriate data protection practices, participates in peer review and quality assurance, and escalates critical findings quickly to support timely mitigation
  • Produces high-quality client deliverables, including test plans, technical reports, and executive readouts, with clear evidence, proof-of-exploit artifacts, risk ratings, reproduction steps, and prioritized remediation recommendations, and facilitates results discussions and remediation workshops
  • Facilitates red team style engagements in collaboration with client SOC teams by coordinating deconfliction, leveraging SIEM telemetry to validate detection and response, and supporting threat hunting and purple team activities tied to observed attacker behaviors
  • Performs validation and retesting to confirm remediation effectiveness and documents retest results for client stakeholders
  • Maintains internal offensive security tooling, scripts, and reusable testing components, including automation and…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary