Junior Pentester

37 minutes ago
Full-time
Junior
Cybersecurity
Thoropass

Thoropass

Thoropass is the leading end-to-end compliance solution that offers expert guidance, thorough preparation, and a seamless security audit experience. With smart software and expert services, Thoropass helps businesses achieve and maintain information se...

Internet Software & Services
51-250
Founded 2019
$98M raised

Description

  • Perform web application, API, mobile, LLM, cloud, and network penetration tests using manual techniques and AI-assisted tools.
  • Follow OWASP Testing Guide methodologies and Thoropass internal playbooks.
  • Validate AI-generated testing results manually and assess the limitations of automated output.
  • Document vulnerabilities with reproduction steps, evidence, risk ratings, and remediation recommendations.
  • Support senior testers with scoping calls and pre-engagement preparation.
  • Improve internal testing templates, skills, plugins, MCPs, checklists, and documentation.
  • Progress toward handling more complex engagements with increasing autonomy.

Requirements

  • 1–2 years of experience in penetration testing, vulnerability assessment, or a related offensive security role; internships, freelance work, and bug bounty experience count.
  • At least one of the following certifications: BSCP or OSCP.
  • Foundational knowledge of web application security, including the OWASP Top 10, authentication and session-management flaws, and injection vulnerabilities.
  • Ability and willingness to use AI tools while manually validating their output.
  • Demonstrated security experience through self-study, labs, CTFs, bug bounties, personal projects, or relevant coursework.
  • Published security research, responsible disclosures, blog posts, or conference talks preferred.
  • Fluent English and strong professional written and verbal communication skills.
  • Curiosity, self-direction, and an attacker mindset focused on identifying and chaining vulnerabilities.

Benefits

  • Competitive base salary.
  • Exceptional private healthcare.
  • Early equity in a fast-growing company.
  • Work-from-home model with flexible PTO.
  • Structured growth path with mentorship and regular feedback.
  • Budget for training, certifications, and conferences.
  • Company-provided laptop.
  • Monthly wellness and home Wi-Fi stipend.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

IT Systems Audit SME (SAP WMS)

C5MI 11-50 Internet Software & Services

C5MI is seeking an IT Systems Audit SME to lead audit readiness, internal-control evaluation, risk management, and compliance activities for mission-critical DoD/DLA warehouse management and SAP environments.

Cybersecurity
5 days, 1 hour ago

Principal Technical Consultant - Network & Security Solution Architect

AHEAD 1K-5K IT Services

AHEAD is seeking a Solution Architect – Network & Network Security to lead the design and delivery of enterprise-scale network and security solutions for a complex Fortune 10 client environment.

Azure Cisco Network Security
6 days ago

Technical Consultant

AHEAD 1K-5K IT Services

AHEAD is seeking a Technical Consultant to help enterprise clients improve cloud security and compliance through consulting delivery, business development, and security practice development.

AWS Azure Bash CI/CD Docker Kubernetes PowerShell Python SIEM Splunk Terraform
1 week, 1 day ago

Senior Professional Services Technical Architect - Security

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Senior Professional Services Technical Architect, Security to design and lead secure enterprise DevSecOps solutions for Professional Services clients across AMER, from pre-sales scoping through implementation and enablement.

Ansible CI/CD DevSecOps GitLab Jenkins SonarQube Terraform
1 week, 2 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers