BreachLock

BreachLock

BreachLock provides a proactive cybersecurity solution that helps organizations identify and remediate potential vulnerabilities to prevent future cyber breaches.

Professional Services
51-250
Founded 2019

Description

  • Execute manual penetration tests for web applications, APIs, and mobile applications, focusing on business logic flaws, authentication abuse, authorization issues, and injection chains.
  • Conduct internal and external network assessments, including assumed breach simulations.
  • Perform Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation activities during internal testing.
  • Use frameworks such as MITRE ATT&CK, PTES, and OWASP to structure assessments and findings.
  • Develop and improve internal tooling, including automation scripts, reporting utilities, and workflow enhancements using Python, Bash, or similar tools.
  • Participate in QA review cycles and provide feedback on findings, CVSS scoring, and report quality.
  • Mentor junior testers by providing technical guidance and reviewing findings.
  • Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance.

Requirements

  • 3–5 years of professional penetration testing experience in a delivery or consulting environment.
  • Strong web application and API testing fundamentals, including Burp Suite proficiency.
  • Experience testing authentication and session management, with knowledge of OWASP Top 10 and beyond.
  • Solid internal network assessment skills, including AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, and assumed breach methodology.
  • Proficiency in scripting and automation with Python, PowerShell, Bash, or similar languages.
  • Strong written communication skills and the ability to write clear, accurate, well-scoped findings independently.
  • Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus.
  • Must be US-based and eligible to work without sponsorship.
  • Preferred experience with C2 frameworks such as Cobalt Strike, Havoc, or Sliver.
  • Active involvement in cybersecurity communities, research, or bug bounty programs is preferred.
  • Certifications such as OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent practical credentials are preferred.
  • Experience with SIEM platforms or EDR tools from an adversarial perspective is preferred.

Benefits

  • Competitive compensation with performance-based equity opportunities.
  • Flexible work hours with hybrid remote options.
  • Opportunity to work with international cybersecurity experts.
  • Strong career progression in a rapidly expanding early-stage company.
  • Exposure to cutting-edge research, tools, and techniques in offensive security.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Vendor Security & Standards Manager

Nebius 51-250 Internet Software & Services

Nebius is seeking a Vendor Security & Standards Manager to globally enforce security compliance across its external supply chain partners, including carriers, 3PLs, freight forwarders, guarding companies, and last-mile providers.

2 days, 23 hours ago

Research Security Consultant

Attain Partners 251-1K Media

Attain Partners is seeking a Research Security Officer to manage university research security and export controls compliance programs within a higher-education and research environment.

5 days ago

Global Safety and Security Lead, Workplace and Facilities

Gong 251-1K Internet Software & Services

Gong is hiring a Global Safety and Security Lead to build and run worldwide safety, security, and business continuity programs that keep employees and offices safe, compliant, and resilient as the company scales globally.

5 days, 23 hours ago

Red & Purple Team Operator

SIXGEN 51-250 Professional Services

SIXGEN is hiring a Senior Red & Purple Team Operator to independently run advanced offensive security assessments and collaborative detection-validation exercises for government and critical infrastructure clients.

Active Directory AWS Azure Cybersecurity Linux Penetration Testing
1 week ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers