Skip to main content
HimalayasHimalayas logo
BreachLockBR

Senior Penetration Tester (US)

BreachLock is a global leader in continuous attack surface discovery and penetration testing, combining human expertise with AI-driven automation to help organizations discover, prioritize, and mitigate cybersecurity exposures before they become breaches.

BreachLock

Employee count: 51-200

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Company Description

BreachLock is a global leader in Offensive Security including Red Teaming, Continuous Attack Surface Discovery and Penetration Testing services. We help organizations discover, prioritize, and mitigate exposures with evidence-backed Attack Surface Management, Penetration Testing, and Red Teaming. BreachLock provides an attacker's perspective that goes beyond standard vulnerabilities, enabling organizations to build a comprehensive, proactive defense strategy.

Role Description

Penetration Tester (Mid-Senior) | Full-Time | Remote (US)

As a penetration tester on BreachLock's US Strategic delivery team, you'll execute manual, methodology-driven engagements across web applications, APIs, and internal networks — including assumed breach simulations — for enterprise clients. You'll work directly with delivery leadership, contribute to internal tooling and quality systems, and help raise the bar for the team around you.

Key Responsibilities

  • Execute web application, API and mobile penetration tests with a focus on manual testing beyond automated scanning — business logic, authentication abuse, authorization flaws, and injection chains
  • Conduct internal network assessments, external network assessments and assumed breach engagements, including Active Directory enumeration, lateral movement, privilege escalation, and post-exploitation
  • Leverage frameworks including MITRE ATT&CK, PTES, and OWASP to structure assessments and findings
  • Develop and contribute to internal tooling — automation scripts, reporting utilities, and workflow improvements using Python, Bash, or similar
  • Participate in QA review cycles, providing structured feedback on findings, CVSS scoring accuracy, and report quality
  • Mentor junior testers through technical guidance and finding review
  • Collaborate with delivery leadership on scoping, client kickoff calls, and remediation guidance

Requirements

  • 3–5 years of professional penetration testing experience in a delivery or consulting context
  • Strong web application and API testing fundamentals — Burp Suite proficiency, OWASP Top 10 and beyond, authentication and session management testing
  • Solid internal network assessment skills — AD enumeration, Kerberoasting, NTLM relay, ADCS misconfigurations, assumed breach methodology
  • Proficiency in scripting and automation (Python, PowerShell, Bash)
  • Strong written communication — capable of writing clear, accurate, well-scoped findings independently
  • Familiarity with PTaaS delivery models or platform-based reporting workflows is a plus
  • US-based and eligible to work without sponsorship

Preferred

  • Experience with C2 frameworks (Cobalt Strike, Havoc, Sliver, or similar)
  • Active involvement in cybersecurity communities, research, or bug bounty programs
  • Certifications such as OSCP, BSCP, CRTO, GWAPT, GPEN, or equivalent practical credentials
  • Experience with SIEM platforms or EDR tools from an adversarial perspective

Benefits

  • Competitive compensation and performance-based equity opportunities
  • Flexible work hours with hybrid remote options
  • Opportunity to work with international cybersecurity experts
  • Strong career progression in a rapidly expanding early-stage company
  • Exposure to cutting-edge research, tools, and techniques in offensive security

Additional Organization Details

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Experience

3 years minimum

Location requirements

Hiring timezones

United States +/- 0 hours

About BreachLock

Learn more about BreachLock and their company culture.

View company profile

In 2019, Seemant Sehgal, having spent years as Head of Global Red Team for one of the world's largest banks, recognized a critical gap in the cybersecurity industry. Managing a multi-million-dollar cybersecurity budget gave him unique insight into the four fundamental pitfalls of traditional penetration testing: accuracy, agility, scalability, and cost-effectiveness. Rather than accept these limitations, he decided to build a solution that would transform how organizations approach offensive security.

BreachLock was born from this vision - a company dedicated to making cyberspace a safe place by helping organizations find and fix their next cyber breaches before they happen. The company pioneered Human-led/AI-driven penetration testing, combining the expertise of ethical hackers with cutting-edge automation to deliver faster, more accurate, and more cost-effective security assessments. Today, BreachLock serves over 1,000 clients across more than 20 countries, having completed over 30,000 penetration testing engagements with 100% year-over-year growth. The company has evolved into a global leader in Continuous Attack Surface Discovery and Penetration Testing, offering services that include PTaaS, Attack Surface Management, Red Team as a Service, and Adversarial Exposure Validation.

Employee benefits

Learn about the employee benefits and perks provided at BreachLock.

View benefits

Competitive Compensation

Market-leading salary packages for talent

Company Car Lease Benefits

Vehicle lease programs for eligible employees

Relocation Benefits

Support for employees relocating for positions

Private Health Insurance

Comprehensive health insurance coverage for employees

View BreachLock's employee benefits
Claim this profileBreachLock logoBR

BreachLock

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

5 remote jobs at BreachLock

Explore the variety of open remote roles at BreachLock, offering flexible work options across multiple disciplines and skill levels.

View all jobs at BreachLock

Remote companies like BreachLock

Find your next opportunity by exploring profiles of companies that are similar to BreachLock. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan