
Penetration Tester
Bishop Fox · United States
- Hybrid
- Full-time
- $120,000 / year
- United States
This role may have been filled. Drop your résumé and we'll check if it's still open — or find you similar roles.
Job highlights
- Penetration tester for offensive security at Bishop Fox.
- Test web apps, hack networks, and reverse software.
- Work with Fortune 100 clients on complex challenges.
- Collaborate with a curious, dedicated, global team.
- Remote work anywhere in the United States.
About the role
Penetration Tester - Bishop Fox
At Bishop Fox, security isn't just a job—it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation.
Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions—including 16 open-source tools and 50 security advisories published in the past five years—we're committed to making the digital world safer.
We’re looking for talented, experienced professional hackers to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US and internationally-based teams supporting clients across multiple industries.
Responsibilities
- You’re a penetration tester who knows their way around source code. You’ve plundered apps and pillaged networks (legally, of course).
- You have a passion for hacking and information security.
- You may also have written a few blog posts about your favorite hacks or have presented at a handful of conferences – with an eye to doing more.
- With Bishop Fox, your responsibilities would include testing web applications, hacking networks, and reversing software.
- As a consultant, you’ll work on a variety of projects which include short-term engagements and extended program work with well-established clients.
- You'll solve challenging technical problems and build creative solutions.
- As a trusted advisor, you’ll provide your expert opinion to help our clients navigate difficult business decisions.
Requirements
- 4+ years experience in planning, conducting, and managing web application penetration tests.
- 5+ years of application security experience.
- Deep understanding of security fundamentals (OWASP), common vulnerabilities, and application security best practices.
- Skilled in vulnerability assessment and the development of exploits for diverse targets.
- Background in system and network security, authentication and security protocols, and applied cryptography is helpful.
- Experience with programming and scripting languages such as Python, Ruby, PowerShell, Java, JavaScript, etc.
- Bonus if you have experience reviewing Golang source code for vulnerabilities.
- Proficiency with operating systems- Linux, Windows, MacOS.
- Experience with network and system exploitation including modern tactics, techniques, and procedures (e.g. c2 frameworks, EDR bypass, privilege escalation, password cracking, lateral movement, etc.).
- Strong technical reporting and documentation skills.
- Advanced relevant academic training, such as a degree in Computer Science or an OSCP, is a definite bonus.
- Experience with AWS cloud environments preferred with an understanding of its major technologies, such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambdas, and how to keep them secure.
- Secondary expertise in one or more of the following areas preferred: Cloud Security Assessments, Mobile Application Security Testing, Hybrid Application Assessments, or AI/LLM Security Assessments.
- Ability to communicate technical findings clearly to both technical and executive stakeholders, including actionable remediation guidance.
Bishop Fox has always allowed its employees to work remotely, and this role could work anywhere in the United States. Our comprehensive benefits program is tailored to meet your needs at an affordable price. We embrace diversity and an inclusive culture. We value our employees and who they are, which fosters a powerful and collective talent base to successfully serve our clients and the security community with unparalleled expertise.
Bishop Fox is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. All new hires must pass a background check as a condition of employment.
Interested? Apply today!
Key skills/competency
- Penetration Testing
- Web Application Security
- Network Hacking
- Software Reversing
- Vulnerability Assessment
- Exploit Development
- Programming Languages (Python, Ruby, etc.)
- Cloud Security (AWS)
- Security Reporting
- Offensive Security
Skills & topics
- Penetration Tester
- Offensive Security
- Web Application Security
- Network Security
- Vulnerability Assessment
- Exploit Development
- Application Security
- Python
- Ruby
- AWS Security
- Hacking
- Information Security
- Cybersecurity
How to get hired
- Tailor your resume: Highlight 4+ years in web app penetration tests and 5+ years in application security. Emphasize your experience with programming languages like Python and scripting, network exploitation, and OS proficiency (Linux, Windows, MacOS).
- Showcase your passion: Detail any blog posts on hacking or conference presentations. Mention specific exploit development, vulnerability assessment, and any experience with modern TTPs like C2 frameworks.
- Emphasize cloud skills: Clearly list your experience with AWS environments and technologies (IAM, EC2, VPC, etc.), and any secondary expertise in cloud, mobile, or AI/LLM security assessments.
- Prepare for technical interviews: Be ready to discuss your approach to testing, specific tools and techniques, and how you communicate findings. Practicing reporting and documentation is key.
- Research Bishop Fox: Understand their leadership in offensive security, their Cosmos platform, and their commitment to open-source contributions. Align your application with their innovative and client-focused culture.
Technical preparation
Behavioral questions
Frequently asked questions
- What are the primary responsibilities of a Penetration Tester at Bishop Fox?
- As a Penetration Tester at Bishop Fox, you will be responsible for conducting web application penetration tests, hacking networks, and reversing software. You will also work on diverse client projects, solve complex technical problems, and provide expert opinions to help clients make informed business decisions. This role requires a deep understanding of security fundamentals and the ability to communicate technical findings clearly.
- What experience is required for the Penetration Tester role at Bishop Fox?
- The role requires a minimum of 4+ years of experience in planning, conducting, and managing web application penetration tests, and 5+ years of application security experience. A strong understanding of security fundamentals (OWASP), common vulnerabilities, exploit development, programming/scripting languages (Python, Ruby, etc.), and operating systems (Linux, Windows, MacOS) is essential. Experience with AWS cloud environments is preferred.
- Is the Penetration Tester position remote at Bishop Fox?
- Yes, Bishop Fox offers remote work for this Penetration Tester position, allowing you to work from anywhere within the United States. The company has a long-standing practice of supporting remote employees and values flexibility.
- What kind of programming languages are important for this Penetration Tester job?
- Proficiency with programming and scripting languages such as Python, Ruby, PowerShell, Java, and JavaScript is important for this Penetration Tester role. Experience reviewing Golang source code for vulnerabilities is considered a bonus. These skills are crucial for various aspects of penetration testing, including exploit development and automation.
- How does Bishop Fox approach offensive security and penetration testing?
- Bishop Fox is a leader in continuous offensive security and penetration testing, dedicated to safeguarding digital landscapes. They are known for their innovative approach, exemplified by their Cosmos platform, and have a strong commitment to research, contributing to open-source tools and publishing security advisories. They partner with top global organizations to secure their systems against real-world threats.
- What are the preferred secondary expertise areas for a Penetration Tester at Bishop Fox?
- Beyond core penetration testing skills, Bishop Fox prefers candidates with secondary expertise in areas such as Cloud Security Assessments, Mobile Application Security Testing, Hybrid Application Assessments, or AI/LLM Security Assessments. These specialized skills enhance a candidate's profile for this role.