BreachLock

BreachLock

BreachLock provides a proactive cybersecurity solution that helps organizations identify and remediate potential vulnerabilities to prevent future cyber breaches.

Professional Services
51-250
Founded 2019

Description

  • Execute manual penetration tests for web applications, APIs, and mobile applications, focusing on business logic flaws, authentication abuse, authorization issues, and injection chains.
  • Conduct internal and external network assessments, including assumed breach simulations.
  • Perform Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation activities during internal testing.
  • Use frameworks such as MITRE ATT&CK, PTES, and OWASP to structure assessments and findings.
  • Develop and improve internal tooling, including automation scripts, reporting utilities, and workflow enhancements using Python, Bash, or similar tools.
  • Participate in QA review cycles and provide feedback on findings, CVSS scoring, and report quality.
  • Mentor junior testers by providing technical guidance and reviewing findings.
  • Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance.

Requirements

  • 3–5 years of professional penetration testing experience in a delivery or consulting environment.
  • Strong web application and API testing fundamentals, including Burp Suite proficiency.
  • Experience testing authentication and session management, with knowledge of OWASP Top 10 and beyond.
  • Solid internal network assessment skills, including AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, and assumed breach methodology.
  • Proficiency in scripting and automation with Python, PowerShell, Bash, or similar languages.
  • Strong written communication skills and the ability to write clear, accurate, well-scoped findings independently.
  • Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus.
  • Must be US-based and eligible to work without sponsorship.
  • Preferred experience with C2 frameworks such as Cobalt Strike, Havoc, or Sliver.
  • Active involvement in cybersecurity communities, research, or bug bounty programs is preferred.
  • Certifications such as OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent practical credentials are preferred.
  • Experience with SIEM platforms or EDR tools from an adversarial perspective is preferred.

Benefits

  • Competitive compensation with performance-based equity opportunities.
  • Flexible work hours with hybrid remote options.
  • Opportunity to work with international cybersecurity experts.
  • Strong career progression in a rapidly expanding early-stage company.
  • Exposure to cutting-edge research, tools, and techniques in offensive security.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Technical Consultant - Network & Security Solution Architect

AHEAD 1K-5K IT Services

AHEAD is seeking a Solution Architect – Network & Network Security to lead the design and delivery of enterprise-scale network and security solutions for a complex Fortune 10 client environment.

Azure Cisco Network Security
28 minutes ago

Technical Consultant

AHEAD 1K-5K IT Services

AHEAD is seeking a Technical Consultant to help enterprise clients improve cloud security and compliance through consulting delivery, business development, and security practice development.

AWS Azure Bash CI/CD Docker Kubernetes PowerShell Python SIEM Splunk Terraform
2 days, 1 hour ago

Senior Professional Services Technical Architect - Security

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Senior Professional Services Technical Architect, Security to design and lead secure enterprise DevSecOps solutions for Professional Services clients across AMER, from pre-sales scoping through implementation and enablement.

Ansible CI/CD DevSecOps GitLab Jenkins SonarQube Terraform
3 days ago

Lead Security Engineer - Penetration Testing & AI Security

HighLevel 251-1K Internet Software & Services

HighLevel is seeking a Lead Security Engineer to secure its SaaS platform and AI-enabled products through application security leadership, secure development practices, and adversarial testing of AI systems.

Bash CI/CD Cybersecurity DevSecOps Docker Go JavaScript JWT Kubernetes Microservices OpenID Connect OWASP Penetration Testing Python SAML
6 days, 1 hour ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers