Penetration Tester
$130,000 to $165,000 per year
ApplyPenetration Tester
Posted 6 days ago
SENIORITY
Lead
SALARY
$130,000 to $165,000 per year
About the role
- Perform controlled penetration testing of NinjaOne applications, cloud environments, and infrastructure, demonstrating exploitability and documenting risks and remediation steps
- Perform security testing of new and modified API endpoints and features as part of each release cycle, prioritizing coverage against release timelines
- Collaborate with Engineering to validate vulnerabilities, communicate impact, and support secure design and remediation efforts
- Develop custom tools or scripts to support penetration testing, automation, and exploit development
- Perform first-pass triage and validation of bug bounty submissions: reproduce reported issues, assess severity and impact (CVSS), identify duplicates, and route confirmed findings to the appropriate teams
- Communicate directly with external security researchers in clear, professional written English throughout the report lifecycle
- Stay current on emerging threats, TTPs, and cybersecurity trends, applying them to evaluate NinjaOne's exposure and guide security initiatives
- Create clear, comprehensive reports and presentations for both technical and executive stakeholders
- Promote security awareness across the organization, contributing to policies, best practices, and ongoing security education
- Other duties as needed
- Bachelor's degree in Information Technology, Computer Science, or a related field 8+ years of hands-on penetration testing experience, within a broader 5+ years in cybersecurity-related roles
- Strong understanding of security protocols, cryptography, authentication/authorization, and modern attack techniques
- Security certifications such as OSCP (highly desired) and/or Security+, CISSP, or CISM are a plus
- Proficiency with penetration testing tools such as Burp Suite, Caido, and related frameworks
- Experience validating and scoring vulnerabilities (CVSS) and communicating findings to both technical and non-technical audiences; bug bounty triage or program experience is a strong plus
- Ability to develop custom testing tools or scripts (Java, Kotlin, C++, Python, or Go)
- Knowledge of security frameworks and methodologies (OWASP, NIST, BSIMM), threat modeling (STRIDE, DREAD), and system hardening standards (CIS, CSA)
- Solid understanding of Linux and Windows operating systems, enterprise architecture, and TCP/IP and UDP networking fundamentals
- Experience testing or exploiting cloud-native applications; understanding cloud security architecture is a plus
- Strong analytical and problem-solving skills with excellent written and verbal communication; this role communicates directly with external security researchers, engineers, and leadership
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
