Velero Consulting Logo

Velero Consulting

Penetration Tester

Posted 17 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United States
120-160 Hourly
Mid level
In-Office or Remote
Hiring Remotely in United States
120-160 Hourly
Mid level
Conduct web, mobile, API, network, and social engineering penetration tests; identify vulnerabilities, develop technical reports, recommend mitigations, and present findings to clients. Ensure assessments align with GDPR, PCI-DSS, SOC 2, and other standards while tracking emerging threats. The role is remote and contract-based, with cloud security, certifications, mobile testing, API security, and scripting experience preferred.
The summary above was generated by AI

Velero is a cybersecurity and compliance consulting firm helping clients navigate complex regulatory requirements through expert-led assessments, advisory services, and practical security execution. Working across the computer and network security space, we partner with organizations to strengthen their security posture with clear, actionable guidance grounded in real-world risk.

In this role, you will help clients uncover vulnerabilities across a range of environments and contribute to security assessments that support both technical resilience and regulatory readiness. This is an opportunity for a penetration tester who enjoys tackling varied engagements, communicating findings clearly, and translating complex security issues into practical next steps for internal teams and clients.

Responsibilities
  • Conduct penetration tests on web applications, mobile applications, and APIs to identify vulnerabilities and potential exploits.
  • Perform network penetration testing, including internal and external network assessments, to ensure comprehensive coverage of security weaknesses.
  • Implement social engineering techniques such as phishing campaigns to simulate real-world attacks and identify human-related security risks.
  • Prepare detailed technical reports and provide actionable recommendations based on the results of penetration tests.
  • Collaborate with internal teams and external clients to discuss findings, mitigation strategies, and security best practices.
  • Ensure compliance with relevant security standards and regulations, including GDPR, PCI-DSS, SOC 2, and others.
  • Stay up to date on emerging threats, vulnerabilities, and security best practices.

RequirementsRequired Qualifications:
  • Proven experience (3+ years) in penetration testing across web apps, mobile apps, APIs, and network environments.
  • Expertise in internal and external network penetration testing.
  • Knowledge of common security vulnerabilities and attack vectors, such as those listed in OWASP Top 10 and MITRE ATT&CK.
  • Familiarity with industry-standard tools like Burp Suite, Nmap, Metasploit, Wireshark, Nessus, and others.
  • Experience with cloud environments (AWS, Azure, Google Cloud) is a plus.
  • Strong understanding of GDPR, PCI-DSS, SOC 2, and other regulatory frameworks.
  • Excellent verbal and written communication skills, with the ability to present findings to technical and non-technical audiences.
Preferred Skills & Certifications:
  • Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), GIAC Penetration Tester (GPEN), or similar certifications.
  • Experience with mobile security frameworks and tools such as OWASP Mobile Security Testing Guide (MSTG).
  • Experience in API security testing, including OAuth and other common API security models.
  • Proficiency in one or more programming/scripting languages (Python, Bash, JavaScript, etc.).

Benefits

This position offers a flexible, remote contract opportunity for penetration testers looking to work on exciting security challenges in a nearshore environment. If you are a skilled security professional passionate about identifying vulnerabilities and strengthening security, we'd welcome your application.Why Join Us?

  • Competitive compensation of 120-160 USD per hour.
  • Flexibility of remote work with a nearshore focus.

Similar Jobs

10 Days Ago
Remote or Hybrid
17 Locations
130K-165K Annually
Senior level
130K-165K Annually
Senior level
Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Perform penetration testing across applications, APIs, cloud environments, infrastructure, and client-side components. Identify, validate, score, and document vulnerabilities; support remediation and secure design with Engineering; triage bug bounty submissions; develop testing tools and scripts; and communicate findings to researchers, technical teams, and executives. The role also applies threat modeling, security frameworks, and emerging threat intelligence to improve organizational security.
Top Skills: AuthenticationAuthorizationBsimmBurp SuiteC++CaidoCisCloud Security ArchitectureCryptographyCsaCvssDreadGoJavaKotlinLinuxNistOwaspPythonStrideTcp/IpUdpWindows
6 Days Ago
Remote
TX, USA
Expert/Leader
Expert/Leader
Security
Conduct web, network, mobile, and red-team penetration tests for government clients. Manage engagements from scoping through reporting, identify and exploit vulnerabilities, provide remediation guidance, and present findings to technical and executive stakeholders. Support cloud security architecture, digital forensics, malware reverse engineering, enterprise security engineering, tool evaluation, and methodology development. The role also contributes to strategic cybersecurity planning and advises clients and senior management on advanced security initiatives.
Top Skills: AdbAndroidBurp Suite ProCloud SecurityDigital ForensicsFfufFridaGraphQLiOSMalware Reverse EngineeringMobsfNistNucleiObjectionOwasp MasvsOwasp MstgOwasp Top 10Owasp WstgRestSoapSqlmap
23 Days Ago
Remote
2 Locations
90K-130K Annually
Mid level
90K-130K Annually
Mid level
Information Technology • Cybersecurity
Conduct infrastructure penetration tests, cloud security assessments, Active Directory reviews, red team operations, adversary simulations, and purple team exercises across on-premises, hybrid, and cloud environments. Identify and validate vulnerabilities, execute attack scenarios, prepare technical reports, present findings, advise clients on remediation, and improve offensive security methodologies, tooling, documentation, and service offerings. The role also requires managing engagement timelines, collaborating with consultants, and maintaining expertise in emerging attack techniques.
Top Skills: Active DirectoryAWSCi/Cd PipelinesCloud-Native TechnologiesEnterprise NetworkingGoogle Cloud PlatformKubernetesLinuxAzureMicrosoft Entra IdVirtualization PlatformsWindowsWireless Networks

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account