Penetration Tester
Listed on 2026-08-03
-
IT/Tech
Cybersecurity
Penetration Tester
Department: Offensive Security
Employment Type: Full Time
Location: Remote - United States
DescriptionWith 30 years of experience in cyber defense, Deep Seas is trusted by nearly 1,000 clients around the world, including Fortune 100 enterprises and mid-market organizations, higher education institutions, municipality and local governments, and federal agencies. Known for its programmatic approach to continuously transforming cyber defense programs, Deep Seas is recognized by Gartner as a top 40 provider of MDR and ranked as a top 5 MDR leader in the 2024 Frost Radar™:
Global Managed Detection and Response (MDR) Market. In addition to its industry-leading MDR service, Deep Seas offers a full suite of advisory, compliance, and testing services to support clients on their cybersecurity transformation journeys, with an approach to cyber defense that prioritizes technical expertise, tradecraft, and continuous innovation to deliver unparalleled results.
The Penetration Tester is a practicing offensive security professional who independently executes client engagements across Deep Seas' core service lines. This role represents the transition from emerging practitioner to confident, self-sufficient contributor. Penetration Testers own their engagements end-to-end within defined scope, produce client-ready deliverables without heavy oversight, and are developing the depth and breadth needed to tackle increasingly complex environments. This is the primary delivery role on the team and the foundation of the practice's capacity.
Key ResponsibilitiesTechnical Delivery
- Conduct internal and external network penetration tests including enumeration, exploitation, lateral movement, and post-exploitation within defined scope.
- Perform web application assessments aligned to OWASP Top 10 and API security testing standards.
- Conduct basic cloud security assessments (AWS, Azure, GCP) including misconfiguration identification, IAM review, and exposed services enumeration.
- Bring experience with adversarial engagements such as red team and purple team exercises.
- Support AI/LLM security assessments including prompt injection, model abuse scenarios, and OWASP LLM Top 10 coverage under senior guidance.
Reporting & Client Communication
- Produce complete, client-ready findings reports with clear technical narratives, reproduction steps, risk ratings, and remediation guidance.
- Participate in client kick-off calls and debrief walkthroughs, communicating findings professionally to technical and non-technical stakeholders.
- Maintain accurate engagement documentation, time tracking, and artifact organization in project management systems.
Professional Growth & Travel
- Pursue continuous development through assigned training, lab environments, and certification advancement.
- May be required to travel up to 25% of the time.
- Candidates must be U.S. citizens and currently reside within the United States.
Minimum Qualifications
- 2-5 years of professional penetration testing or applied offensive security experience; strong candidates with equivalent demonstrated skills will be considered.
- Proficiency with standard toolsets:
Nmap, Metasploit, Burp Suite, Nessus/OpenVAS, Blood Hound, or equivalents. - Solid understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, AD, VPNs) and common vulnerability classes.
- Familiarity with at least one scripting language (Python, Bash, or Power Shell) for basic automation and tooling.
- Exposure to cloud platforms (AWS, Azure, or GCP) and awareness of common cloud misconfiguration patterns.
- Solid understanding of AI technology in everyday work activities.
- Strong written communication with the ability to produce accurate, professional-quality findings documentation.
Preferred Qualifications
- Hands‑on penetration testing certification, such as PNPT (TCM Security), OSCP (Offensive Security), CompTIA Pen Test+, or eWPT/eJPT with demonstrated experience.
At Deep Seas, we like to say that heart rates go down, careers take off, and security programs mature. Our values provide the ultimate guide for our daily behavior and decisions. Without these values, we aren’t Deep Seas. They…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).