Lead manual, exploit-driven penetration testing across web, API, network, and cloud targets. You will go far beyond scanners, chain real flaws into business impact, and set the technical bar for every finding we ship.
What you will do
Scope and deliver penetration tests across web applications, APIs, internal and external networks, and cloud
Manually exploit and chain vulnerabilities to prove genuine, demonstrable business impact
Develop and adapt exploits, payloads, and tooling when off-the-shelf options fall short
Write clear, prioritized reports engineers can act on and leaders can understand
Brief clients on findings and support them through remediation and verified retest
Mentor junior testers and raise the bar on internal methodology and tooling
What we are looking for
4+ years of hands-on penetration testing across web, API, network, and at least one major cloud
OSCP required; OSWE, OSEP, or CRTO a strong plus and expected within the first year
Deep, manual command of the OWASP Top 10, API and auth flaws, and SSRF/deserialization/injection chains
Proven exploit development or modification skills and fluency in Python and at least one of Bash, Go, or PowerShell
Strong cloud attack knowledge in AWS, Azure, or GCP, including IAM and metadata abuse
Exceptional technical writing - your reports are the product, not the scan output
Nice to have
Mobile, thick-client, or container and Kubernetes security specialization
Published CVEs, research, tooling, or conference talks
Burp Suite extension or custom tooling development
Get ahead of zero
Ready to see yourself the way an adversary would?
Book a scoped assessment - we will map what is reachable, prove what is exploitable, and give you a ranked path to closing it before someone finds it first.