Penetration Tester

Remote • Posted 3 hours ago • Updated 3 hours ago
Contract Corp To Corp
Contract W2
12 Months
Remote
$80 - $90/hr
Fitment

Dice Job Match Score™

🛠️ Calibrating flux capacitors...

Job Details

Skills

Summary

HonorVet Technologies is a veteran-owned IT staffing firm, ISO 9001 and ISO 27001 certified, working with federal agencies, state governments, and Fortune 500 enterprise clients across the US. What makes us different isn''t a tagline — it''s the way we work. We don''t forward resumes and hope for the best. We take the time to understand where a professional like you are headed and only reach out when we genuinely believe there''s a fit worth exploring.
 
Job Title: Penetration Tester      
Location: Remote
Duration: 12 Months (Possible Extension)

Employment type: Contract
 
Job Description:
As a member of our Attack & Pentest team, you will serve as a frontline analyst responsible for validating, prioritizing, and driving the closure of security vulnerabilities across the enterprise. You will assess findings for exploitability and business risk, retest applications and infrastructure after remediation, and work directly with engineering teams to ensure issues are resolved effectively and on schedule. This is a hands-on technical role that requires both offensive security skills and the ability to communicate clearly with developers, architects, and leadership.
 
Key Responsibilities:
  • Triage – Review and validate incoming vulnerability reports from Mythos; assess severity, exploitability, and business impact; de-duplicate and enrich findings with reproduction steps and evidence
  • Retesting – Perform targeted retesting of remediated vulnerabilities to confirm fixes are effective and complete; document pass/fail results with technical evidence
  • Tracking & Remediation Support – Monitor remediation timelines against SLAs; coordinate with development and infrastructure teams to ensure timely closure; escalate aging findings per policy
  • Reporting – Maintain accurate records in the vulnerability management platform; produce weekly status reports on open/closed/overdue findings; contribute to executive-level metrics
  • Collaboration – Partner with application security, DevOps, and engineering teams to provide remediation guidance and technical context for findings
  • Process Improvement – Identify patterns in recurring vulnerabilities; recommend process or tooling improvements to reduce triage backlog.
 
Must have:
  • 3 plus years’ Experience in hands on penetration testing experience or offensive security testing

Required Qualifications:
  • 3+ years of hands-on penetration testing experience (web applications, APIs, infrastructure)
  • Demonstrated experience triaging vulnerabilities at scale (CVSS scoring, CWE/OWASP classification, risk-based prioritization)
  • Strong understanding of common vulnerability classes (OWASP Top 10, SANS Top 25) and remediation strategies
  • Experience with vulnerability management platforms (e.g., Jira, ServiceNow, DefectDojo, or similar)
  • Ability to write clear, reproducible proof-of-concept exploits and remediation validation reports
  • Familiarity with SDLC integration and working directly with development teams on fix guidance
  • Strong written and verbal communication skills; able to translate technical findings for varied audiences.
     
Preferred Qualifications:
  • Relevant certifications: OSCP, GPEN, GWAPT, CEH, or equivalent
  • Experience with bug bounty or crowdsourced vulnerability programs
  • Familiarity with financial services regulatory requirements (PCI-DSS, FFIEC, SOX)
  • Scripting/automation skills (Python, Bash, Burp extensions) for retesting workflows
  • Experience with CI/CD pipeline security tooling (SAST/DAST integration)
  • Tools & Environment (Preferred Familiarity)
  • Burp Suite Professional, Nuclei, Caido
  • Git-based workflows and code review
  • Cloud platforms (AWS, Azure, Google Cloud Platform) security configurations
  • Container/Kubernetes security fundamentals
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90941473
  • Position Id: 26-16702
  • Posted 3 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Easy Apply

Contract

Up to $92.3

Remote

Today

Easy Apply

Contract

60 - 70

Remote

Today

Easy Apply

Third Party, Contract

60 - 70

Remote

Today

Easy Apply

Contract

Depends on Experience

Search all similar jobs