
Senior Penetration Tester - Cloud at Bishop Fox. Location Information: U.S. Remote. . Bishop Fox, security isn’t just what we do, it’s what we . live. for. We lead the way in continuous offensive security and penetration testing, helping some of the most recognizable companies on the planet stay ahead of real world threats. We’re trusted by over a quarter of the Fortune 100, half of the Fortune 10, and the biggest names in media, tech, and finance. . . Our Cosmos platform (shoutout to SC Media for naming it Best Emerging Technology) is just one example of how we keep pushing the envelope. And with nearly two decades of contributions, from open-source tools to published advisories, we’re all in on making the digital world safer. . . We’re looking for talented, experienced professional hackers to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US teams supporting clients across multiple industries. . . Responsibilities. . . You’re a penetration tester who knows their way around source code. You’ve plundered apps and pillaged networks (legally, of course). You have a passion for hacking and information security. You may also have written a few blog posts about your favorite hacks or have presented at a handful of conferences – with an eye to doing more. . . With Bishop Fox, your responsibilities would include diving into Cloud security, testing web applications, hacking networks, and reversing software. As a senior consultant, you’ll work on a variety of projects which include short-term engagements and extended program work with well-established clients. You'll solve challenging technical problems and build creative solutions. As a trusted advisor, you’ll provide your expert opinion to help our clients navigate difficult business decisions. . . Requirements. . . . 4+ years experience in planning, conducting, and managing web application penetration tests . . 5+ years of hands-on experience in cloud security and application security . . Understanding of its major technologies, such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambdas, and how to keep them secure . . Experience with cloud platforms and technologies including Azure, GCP, Docker, and Kubernetes . . Deep understanding of security fundamentals (OWASP), common vulnerabilities, and application security best practices . . Skilled in vulnerability assessment and the development of exploits for diverse targets . . Background in system and network security, authentication and security protocols, and applied cryptography is helpful . . Experience with programming and scripting languages such as Python, Ruby, PowerShell, Java, JavaScript, etc. . . Proficiency with operating systems- Linux, Windows, MacOS . . Experience with network and system exploitation including modern tactics, techniques, and procedures (e.g. c2 frameworks, EDR bypass, privilege escalation, password cracking, lateral movement, etc.) . . Experience with IPTs and infrastructure with large-scale scopes . . Strong technical reporting and documentation skills . . Advanced relevant academic training, such as a degree in Computer Science or an OSCP, is a definite bonus . . . Bishop Fox has always allowed its employees to work remotely, and this role could work anywhere in the United States. Our comprehensive benefits program is tailored to meet your needs at an affordable price. We embrace diversity and an inclusive culture. We value our employees and who they are, which fosters a powerful and collective talent base to successfully serve our clients and the security community with unparalleled expertise. . . Bishop Fox is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. All new hires must pass a background check as a condition of employment.. . . Interested? Apply today! . .