Skip to main content
Schellman

Senior Penetration Tester

RemoteUnited States only
Published
Role
Security
Experience
Senior
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior Penetration Tester with 3+ years of hands-on experience and 1+ year in web application penetration testing. Must hold OSCP certification. Requires proficiency in common OS, cloud concepts, and at least two scripting languages (Python, Bash, JS, PowerShell).

Core skills

penetration testingweb application penetration testing

Required skills

PythonBashJavaScriptPowerShellOSCP

Optional skills

CRTOBurp Suite Certified PractitionerPCIFedRAMP

Required languages

English

What you'll do

  • Complying with Schellman’s code of ethics and professional conduct, methodologies, policies, and procedures
  • Adhering to the professional and regulatory standards relevant to assigned service line specialization(s)
  • Promoting Schellman’s company culture and exemplifying Schellman's values
  • Establishing high quality relationships and rapport with client personnel
  • Managing client expectations to ensure expectations are exceeded
  • Completing assigned duties in a timely manner and with a high attention to detail
  • Collaborating with fellow project team members in a productive and timely manner throughout the life cycle of each project
  • Adhering to project schedules and keeping fellow project team members apprised of the progress of assigned tasks
  • Escalating issues internally in a proper and timely manner
  • Using discretion and decorum in the timing, form, and content of all client communications
  • Booking travel reservations in a timely manner and in accordance with Schellman's travel and expense policies and procedures
  • Performing the essential functions of other service delivery positions when qualified and called upon to do so
  • Attending project kick-off and closing meetings
  • Executing assigned testing procedures, performing detailed analysis, reaching conclusions, documenting results in accordance with company standards, and suggesting ideas for improvements, where applicable
  • Drafting project deliverables
  • Serving as a contact for clients' basic questions regarding an engagement
  • Participating in recruiting and candidate interview activities
  • Training project team members
  • Acclimating newer team members to Schellman
  • Contributing to Schellman's practice development efforts
  • Developing an expert knowledge of professional and regulatory standards relevant to assigned service line specialization(s)
  • Contributing to Schellman's thought leadership (e.g., articles, webinars, public speaking, etc.)

What they require

  • 3+ years’ experience in hands on penetration testing
  • 1+ year experience in web application penetration testing
  • Ability to work well independently, within a team and with clients
  • Completion of one or more of the following certifications: Offensive Security Certified Professional (OSCP) (Required)
  • Demonstrated enthusiasm for Information Security (e.g. GitHub repo, blogs, presentations, conference talks, local security association member, participated in free skill-building / hacking challenges – SANS Holiday Hack, HackerOne CTF, HackTheBox, etc.)
  • Competency in common operating systems (e.g. Windows, macOS, Linux)
  • An understanding of cloud computing models, technologies, and concepts
  • Proficiency with at least two scripting languages (e.g. Python, Bash, JavaScript, PowerShell)
  • Knowledge of PCI and FedRAMP programs
  • A passion for identifying and exploiting vulnerabilities
  • Demonstrated entrepreneurial abilities, client focus, industry savvy, and the ability to work independently or as part of a collaborative team
  • Self-driven in a remote working environment, motivation to continuously improve your skillset

Benefits

  • Opportunity to transition to a focused penetration testing position to build on your offensive skillset while working on engagements with our team, whose unrivaled knowledge and experience will provide guidance and mentorship throughout.
  • Remote work opportunity
  • Continuous education
  • Some travel annually, which can include in-person training, team meet-ups, and strategy meetings.
  • Service Delivery team members will also be required to travel based on business and client needs.

Schellman is a Top 50 CPA firm and a leading provider of attestation and compliance services. Our professional services focus on security and privacy audits, assessments, and certifications. Schellman has become one of the largest cybersecurity assessment firms in the United States without providing any traditional accounting services. We are an accredited multi-framework ISO Certification Body for security, privacy, business continuity, and quality; a globally licensed PCI Qualified Security Assessor and a top provider to clients serving the federal DoD space as a leading FedRAMP 3PAO and the first assessment firm authorized as a CMMC C3PAO.

CybersecurityEnterprise
Salary not disclosed