Penetration Tester
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, IT Consultant
Join The Team
Cybersecurity is one of the fastest growing industries and Ridge is pioneering Managed IT. Jobs in cybersecurity are expected to grow by 18% over the next 5 years and we are growing too. If you think you're a great fit for our team, apply now.
- Training
- 401k
- Unlimited Coffee
We are seeking a skilled and motivated Penetration Tester to join our team and play a key role in delivering our penetration testing services. In this client-facing role, you will simulate real-world cyberattacks on client networks, applications, cloud environments, and infrastructure to uncover security weaknesses, provide actionable recommendations, and help organizations strengthen their defenses.
You will work closely with clients, account managers, and our Cybersecurity Engineers team to scope engagements, execute tests safely and ethically, and deliver clear, high-impact reports that drive remediation and risk reduction.
Key Responsibilities- Plan, scope, and execute penetration tests (internal, external, web application, mobile, wireless, cloud, and social engineering) for MSP clients across various industries
- Perform manual and automated vulnerability assessments using industry-standard tools and custom techniques
- Identify, exploit, and document security vulnerabilities, misconfigurations, and business logic flaws
- Simulate advanced attack scenarios, including lateral movement, privilege escalation, and persistence techniques in Windows, Linux, and hybrid environments
- Conduct testing in accordance with recognized methodologies (e.g., OWASP, PTES, OSSTMM, NIST) and client-specific rules of engagement
- Produce detailed, professional reports with executive summaries, technical findings, risk ratings, evidence, and prioritized remediation recommendations
- Stay current with emerging threats, attack vectors, new vulnerabilities (CVEs), and penetration testing techniques
Qualifications
Required:
- 3+ years of hands-on penetration testing or related red team / ethical hacking experience
- Deep understanding of common vulnerabilities (OWASP Top 10, CWE Top 25) and exploitation techniques
- Experience writing clear, professional technical reports and communicating findings to both technical and non-technical audiences
- Strong understanding of ethical guidelines and legal requirements for penetration testing
- Excellent problem-solving skills, attention to detail, and ability to work independently on client engagements
Preferred:
- Relevant certifications such as:
- Offensive Security Certified Professional (
OSCP
) – highly preferred - CompTIA Pen Test+
- GIAC Penetration Tester (
GPEN
) - Certified Ethical Hacker (
CEH
) - Or other advanced certs (e.g., OSCE, OSEP, CRTP, PNPT)
- Offensive Security Certified Professional (
- Experience testing in MSP or client-service environments (multi-tenant awareness, scoped engagements)
- Knowledge of compliance frameworks (PCI DSS, HIPAA, SOC 2, NIST 800-53, ISO 27001)
- Experience with cloud penetration testing, API testing, or red team operations
- Active participation in bug bounty programs, CTFs, or security research
Ridge IT Cyber is the top-ranked Managed Security Service Provider (MSSP) on the prestigious Inc. 5000 “America’s Fastest Growing Private Companies” of 2023. Our cutting-edge cybersecurity and IT solutions have established us as an industry leader. With extensive experience serving enterprises, small and medium-sized businesses, private commercial companies, and federal agencies, we have a unique understanding of the challenges in achieving operational goals, ensuring security, and maintaining legal compliance within budgetary constraints.
We streamline our clients’ information technology needs while enhancing their operations through tailored solutions and implementation services.
Ridge IT Cyber is an equal opportunity employer. We are committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions at Ridge IT Cyber are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, national origin, sex, pregnancy, childbirth or related medical conditions, age, marital status, sexual orientation, gender identity, family medical history or genetic information, disability, status as a veteran, or any other basis protected by applicable federal, state or local law.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).