Source Job

Germany

  • Perform penetration tests of IT infrastructures, web applications, and web services.
  • Conduct security assessments in Active Directory, cloud environments (Azure, AWS), and mobile applications.
  • Analyze AI-powered applications and LLM integrations for vulnerabilities and misconfigurations.

Penetration Testing Web Application Security Network Security Cloud Security Scripting

20 jobs similar to Penetration Tester

Jobs ranked by similarity.

$100,000–$130,000/yr
US

  • Perform offensive security assessments on cloud infrastructure, web applications, APIs, and traditional networks for clients across various industries.
  • Develop detailed penetration testing documentation and collaborate with teams to integrate security into CI/CD pipelines.
  • Contribute to building a new offensive security service line within a top-rated CPA and advisory firm.

Aprio is a top 20 CPA-led advisory firm serving fast-growing industries with expertise in assurance, tax, and advisory services. The firm has over 3,200 team members across 40+ offices globally, and is recognized as a Best Place to Work with a collaborative culture.

$155,520–$228,700/yr
US

  • Perform full-stack penetration testing of web applications, APIs, and mobile apps.
  • Conduct internal/external network audits and vulnerability validation.
  • Develop custom exploits, adversary emulation, and AI/LLM security testing.

Twilio is shaping the future of communications by delivering innovative solutions to hundreds of thousands of businesses and empowering millions of developers worldwide. The company values a remote-first work culture, global inclusion, and diverse experiences.

US Unlimited PTO

  • Deliver attack-oriented professional services including penetration testing, red teaming, and social engineering for clients.
  • Author comprehensive assessment deliverables detailing technical execution, core deficiencies, and remediation strategies.
  • Contribute to practice development and marketing initiatives through research, speaking, and tool creation.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services to help organizations minimize risk. The company has over 1,200 employees and focuses on a collaborative, enjoyable workplace atmosphere.

India

  • Lead security initiatives across infrastructure, applications, cloud, and enterprise deployments to ensure a strong security posture.
  • Conduct penetration testing, vulnerability assessments, and security reviews to proactively identify and mitigate risks.
  • Collaborate with engineering, DevOps, and machine learning teams to embed security best practices into products and processes.

The company develops innovative AI-driven products for highly regulated environments. They operate with a startup culture, emphasizing collaboration, autonomy, and continuous improvement.

Europe

  • Define security requirements and design application architectures following a secure-by-default approach.
  • Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
  • Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.

Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.

Slovakia

  • Perform penetration tests and proactively combat cyber attacks.
  • Drive automation in security testing and analysis.
  • Act as a trusted advisor on IT security and collaborate with a specialist team.

Deutsche Telekom System Solutions Slovakia is an IT solutions provider part of the Deutsche Telekom group, focusing on innovative ICT services. With over 3,900 employees, it is the second largest employer in eastern Slovakia, fostering a culture of continuous improvement and transformation.

Indonesia

  • You will lead Ajaib's offensive security program and take a hands-on role in testing the resilience of our technology.
  • You will design and execute penetration tests, red-team exercises, and security assessments across mobile apps, APIs, cloud, and corporate environments.
  • You will partner with engineering and security teams to validate remediation and provide clear guidance to reduce risk without slowing delivery.

Ajaib is an Indonesian investment platform helping people access and manage investments across stocks, crypto, and US stocks. As a growing fintech company, we are committed to protecting our customers, products, and technology to maintain trust.

$202,000–$278,000/yr
US Unlimited PTO

  • Drive product capability by bringing an offensive practitioner's perspective to scanning, fingerprinting, and attack surface data.
  • Conduct original research on emerging attack techniques using Internet-wide scan data and publish findings at major conferences.
  • Collaborate with engineering and product teams to translate research into new scanning modules, fingerprints, and detection features.

Censys provides real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide. The company values collaboration, innovation, and impact, with a team of world-class researchers and engineers.

UK

  • Lead and mentor an internal red team, establishing scalable offensive security practices.
  • Conduct advanced penetration testing and adversarial simulations across cloud infrastructure and AI environments.
  • Research emerging attack techniques and collaborate with detection teams during purple team exercises.

They operate a cutting-edge cloud platform that supports advanced AI workloads. The company is remote-first, emphasizes innovation and continuous improvement, and has a collaborative international team.

UK

  • Perform hands-on security testing and code review across web applications and APIs.
  • Conduct threat modeling and embed secure development practices into the SDLC.
  • Build and tune security tooling, including SAST, DAST, and CI/CD automation.

Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.

US 4w PTO

  • Lead application security reviews, threat modeling, and secure code review for new features and significant product changes.
  • Operate and improve SAST, DAST, and SCA tooling, triage findings, and partner with engineering teams to harden the codebase.
  • Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and own the vulnerability management lifecycle.

ButterflyMX empowers people to automate property access, operations, and security from a single platform, serving over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by a shared commitment to excellence and innovation.

$120,000–$155,000/yr
US

  • Perform Red Team engagements including stealth and purple teaming to simulate advanced cyber attacks and test security posture.
  • Collaborate with blue team members in real time to identify and address security gaps, and document findings for technical and executive audiences.
  • Stay current on attack vectors, develop new tools and techniques, and provide technical leadership to junior team members.

NBCUniversal is a leading media and entertainment company, creating world-class content across film, television, streaming, and theme parks. As a subsidiary of Comcast, we employ a global workforce and foster an inclusive culture focused on innovation and community.

US

  • Design, build, and operate an AI-augmented red teaming harness using frontier LLM APIs.
  • Conduct adversarial testing across four attack perspectives to discover and chain vulnerabilities.
  • Assume ownership of security stage-gates within our CI/CD pipeline.

We provide a cloud-native platform called Silo that enables digital analysts to securely and anonymously investigate threats. We serve over 750 organizations and value integrity, collaboration, and innovation.

$140,000–$140,000/yr
US

  • Lead advanced penetration tests and adversary emulation in ICS/OT environments, performing hands-on exploitation of customer networks and systems.
  • Conduct deep technical analysis of network data to identify attack paths and vulnerabilities, while researching threat actor TTPs.
  • Deliver clear reports and briefings to customers, mentor team members, and contribute to the OT security community.

Dragos defends industrial organizations providing essentials like water, electricity, and safe working environments. As a market leader in ICS/OT cybersecurity, we are remote-first with global operations and seek mission-oriented teammates embodying authenticity, transparency, and trust.

$172,800–$205,200/yr
Europe

  • Enable MSP/MSSP partners through technical training and certifications to independently deliver NodeZero.
  • Support partners in customer-facing opportunities by delivering demos, proofs-of-value, and solution design.
  • Act as a trusted advisor on offensive security, gathering feedback to inform product roadmap.

Horizon3.ai is a fast-growing cybersecurity company that provides autonomous penetration testing with its NodeZero platform. The company is a small team of former U.S. Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, and ownership.

United States

  • Design, build, and operate an AI-augmented red teaming harness using advanced LLM APIs for autonomous vulnerability discovery.
  • Conduct adversarial testing across external, internal, and privileged perspectives, chaining and validating vulnerabilities.
  • Collaborate with DevSecOps, SOC, and engineering teams to improve security automation and detection workflows.

This company provides a cloud-based platform for highly security-conscious organizations. It fosters a remote-first culture focused on innovation, ownership, and continuous learning.

India

  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
  • Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.

Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.

$131,250–$150,000/yr
United States Canada Dominican Republic Unlimited PTO

  • Lead application and product security across Forward-built, third-party, and AI-built software.
  • Evolve the pentest program and proactively build AI solutions within the appsec function.
  • Own remediation workflows and partner with teams to build controls for external exposure.

Forward Financing is a financial technology company that unlocks capital for small businesses across America. They are a recognized Best Place to Work with a remote-first culture and team members across the US, Canada, and Dominican Republic.

Germany

  • Design, build, and operate AI security runtime controls across cloud platforms.
  • Develop and maintain security solutions for AI interactions, LLMs, and agent workflows.
  • Act as senior escalation point for complex AI security incidents.

US

  • Partner with engineering and product teams to identify application security risks and provide practical mitigation recommendations.
  • Analyze code, configurations, and logs to detect vulnerabilities and improve security workflows.
  • Communicate security risks clearly to technical and non-technical stakeholders and drive scalable solutions.