BreachLock

BreachLock

BreachLock provides a proactive cybersecurity solution that helps organizations identify and remediate potential vulnerabilities to prevent future cyber breaches.

Professional Services
51-250
Founded 2019

Description

  • Execute manual penetration tests for web applications, APIs, and mobile applications, focusing on business logic flaws, authentication abuse, authorization issues, and injection chains.
  • Conduct internal and external network assessments, including assumed breach simulations.
  • Perform Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation activities during internal testing.
  • Use frameworks such as MITRE ATT&CK, PTES, and OWASP to structure assessments and findings.
  • Develop and improve internal tooling, including automation scripts, reporting utilities, and workflow enhancements using Python, Bash, or similar tools.
  • Participate in QA review cycles and provide feedback on findings, CVSS scoring, and report quality.
  • Mentor junior testers by providing technical guidance and reviewing findings.
  • Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance.

Requirements

  • 3–5 years of professional penetration testing experience in a delivery or consulting environment.
  • Strong web application and API testing fundamentals, including Burp Suite proficiency.
  • Experience testing authentication and session management, with knowledge of OWASP Top 10 and beyond.
  • Solid internal network assessment skills, including AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, and assumed breach methodology.
  • Proficiency in scripting and automation with Python, PowerShell, Bash, or similar languages.
  • Strong written communication skills and the ability to write clear, accurate, well-scoped findings independently.
  • Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus.
  • Must be US-based and eligible to work without sponsorship.
  • Preferred experience with C2 frameworks such as Cobalt Strike, Havoc, or Sliver.
  • Active involvement in cybersecurity communities, research, or bug bounty programs is preferred.
  • Certifications such as OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent practical credentials are preferred.
  • Experience with SIEM platforms or EDR tools from an adversarial perspective is preferred.

Benefits

  • Competitive compensation with performance-based equity opportunities.
  • Flexible work hours with hybrid remote options.
  • Opportunity to work with international cybersecurity experts.
  • Strong career progression in a rapidly expanding early-stage company.
  • Exposure to cutting-edge research, tools, and techniques in offensive security.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Data Loss Prevention (DLP) Implementation Consultant - Part Time

Muller Internet Software & Services

Data Loss Prevention (DLP) Implementation Consultant at a company deploying enterprise security controls for customer environments, responsible for implementing and operationalizing a DLP solution aligned to security requirements.

Active Directory HIPAA macOS SIEM
1 day, 18 hours ago

Senior Consultant - ICS/OT Cybersecurity

Dragos 251-1K Professional Services

Dragos is hiring a Senior Consultant for its Professional Services team to lead cybersecurity engagements that help industrial organizations protect critical infrastructure.

Active Directory Cybersecurity SIEM SSH
2 days, 18 hours ago

RMF, Security & ATO Manager

Lever 251-1K Professional Services

Latitude IT Solutions is hiring an RMF, Security & ATO Manager to own compliance and authorization for a complex, multi-tenant VA health IT platform.

DevSecOps HIPAA
4 days, 18 hours ago

Business Information Security Officer - Remote/Defense Industrial Base (DIB) Exp

EVOTEK 51-250 IT Services

EVOTEK is hiring a Business Information Security Officer to help lead and evolve the company’s security strategy across business, technology, and compliance initiatives for client-facing operations.

Cybersecurity
4 days, 18 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers