Bishop Fox Logo

Bishop Fox

Penetration Tester - Contract

Posted 19 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in U.S.
Senior level
Remote
Hiring Remotely in U.S.
Senior level
The Penetration Tester will conduct web application penetration tests, identify vulnerabilities, and provide remediation guidance to stakeholders. Candidates should have strong expertise in various security domains such as cloud and network security.
The summary above was generated by AI

Contract Penetration Tester 

At Bishop Fox, security isn't just a job—it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation. 

Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions—including 16 open-source tools and 50 security advisories published in the past five years—we're committed to making the digital world safer.  

We’re looking for talented, experienced professional hackers to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US and internationally-based teams supporting clients across multiple industries.   

Responsibilities 

Bishop Fox is looking for experienced contract penetration testers with a primary focus in web application security and strong secondary expertise in cloud, mobile, source code, network, or AI/LLM security. 

You’ll work on a range of projects, from short-term assessments to longer-term program engagements with well-established clients. In this role, you’ll identify vulnerabilities, validate risk, develop creative solutions, and clearly communicate findings and remediation guidance to both technical and executive stakeholders. As a trusted advisor, you’ll help clients understand risk and make informed security decisions.  

Experience 

  • 5+ years of experience planning, conducting, and managing web application penetration tests
  • Deep understanding of application security fundamentals, OWASP Top 10, common vulnerabilities, and secure development best practices
  • Experience assessing vulnerabilities and developing exploits across diverse targets
  • Strong understanding of system and network security, authentication protocols, security protocols, and applied cryptography
  • Ability to communicate complex technical findings clearly and provide practical remediation guidance to technical and executive audiences 

Preferred Experience 

Deep experience in at least one of the following: 

  • Cloud Security - Experience assessing AWS cloud environments, including technologies such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambda. 
  • Mobile Application Security - Experience testing iOS and/or Android applications, including mobile application architecture, API communication, data storage, authentication flows, and common mobile security vulnerabilities. 
  • Source Assisted Application Assessments: Experience evaluating applications across multiple layers, including source code, APIs, infrastructure, and integrations. Strong proficiency in Golang is highly preferred, along with familiarity in languages such as Python, Ruby, PowerShell, Java, and JavaScript. 
  • Network Security - Experience with network and system exploitation, including modern tactics, techniques, and procedures such as C2 frameworks, EDR bypass, privilege escalation, password cracking, and lateral movement. 
  • AI/LLM Security - Experience assessing non-deterministic security controls. 

Employment Sponsorship

This engagement is for independent contractors (1099) and is not eligible for any form of employment sponsorship. Applicants must be legally authorized to work in the United States without requiring visa sponsorship now or in the future. Applicants must be located in the United States.

All new hires must pass a background check as a condition of employment. 

Bishop Fox is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. 

 

Similar Jobs

23 Days Ago
Remote
United States
Senior level
Senior level
Financial Services
The Senior Penetration Tester is responsible for executing penetration tests, managing client expectations, training team members, and contributing to practice development while demonstrating cybersecurity expertise.
Top Skills: BashBurp SuiteJavaScriptPowershellPython
An Hour Ago
Remote or Hybrid
United States
42K-52K Annually
Entry level
42K-52K Annually
Entry level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
The Associate Customer Support Technician will assist customers with software and hardware inquiries while providing excellent customer service via phone, email, and chat. Responsibilities include troubleshooting, problem resolution, and escalating issues as needed.
Top Skills: FreshdeskJIRAMicrosoft ApplicationsSalesforceTalkdesk
An Hour Ago
Remote or Hybrid
United States
45K-60K Annually
Junior
45K-60K Annually
Junior
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
The Customer Support Technician provides technical assistance and support to customers regarding software and hardware, resolving issues, documenting cases, and contributing to team efforts.
Top Skills: Applied EpicSaaS

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account