NinjaOne Logo

NinjaOne

Penetration Tester

Posted An Hour Ago
Be an Early Applicant
Remote or Hybrid
16 Locations
130K-165K Annually
Senior level
Remote or Hybrid
16 Locations
130K-165K Annually
Senior level
Perform penetration testing across applications, APIs, cloud environments, infrastructure, and client-side components. Identify, validate, score, and document vulnerabilities; support remediation and secure design with Engineering; triage bug bounty submissions; develop testing tools and scripts; and communicate findings to researchers, technical teams, and executives. The role also applies threat modeling, security frameworks, and emerging threat intelligence to improve organizational security.
The summary above was generated by AI

About the Role 

The Penetration Tester role is a key part of NinjaOne's core security team, with visibility across the entire organization, from individual developers to executive leadership. You will directly strengthen the security of the NinjaOne platform by identifying and helping resolve technical, security, and architectural vulnerabilities across our applications and environments. The ideal candidate takes a multi-layered approach to uncovering weaknesses in software, web applications, and client-side components to drive meaningful security improvements. This role is also a key contributor to NinjaOne's public bug bounty program, validating externally reported vulnerabilities and working directly with security researchers around the world.

Location: We are flexible on remote working from home, if you are located in the USA and reside in one of the following states: CA, CO, CT, FL, GA, *IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA. We have physical offices in Austin, TX and Tampa, FL, if you prefer a hybrid option.

*Onsite interviews may be required for this role.

What You'll Be Doing 

  • Perform controlled penetration testing of NinjaOne applications, cloud environments, and infrastructure, demonstrating exploitability and documenting risks and remediation steps
  • Perform security testing of new and modified API endpoints and features as part of each release cycle, prioritizing coverage against release timelines
  • Collaborate with Engineering to validate vulnerabilities, communicate impact, and support secure design and remediation efforts
  • Develop custom tools or scripts to support penetration testing, automation, and exploit development
  • Perform first-pass triage and validation of bug bounty submissions: reproduce reported issues, assess severity and impact (CVSS), identify duplicates, and route confirmed findings to the appropriate teams
  • Communicate directly with external security researchers in clear, professional written English throughout the report lifecycle
  • Stay current on emerging threats, TTPs, and cybersecurity trends, applying them to evaluate NinjaOne's exposure and guide security initiatives
  • Create clear, comprehensive reports and presentations for both technical and executive stakeholders
  • Promote security awareness across the organization, contributing to policies, best practices, and ongoing security education
  • Other duties as needed

About You 

  • Bachelor's degree in Information Technology, Computer Science, or a related field
  • 8+ years of hands-on penetration testing experience, within a broader 5+ years in cybersecurity-related roles
  • Strong understanding of security protocols, cryptography, authentication/authorization, and modern attack techniques
  • Security certifications such as OSCP (highly desired) and/or Security+, CISSP, or CISM are a plus
  • Proficiency with penetration testing tools such as Burp Suite, Caido, and related frameworks
  • Experience validating and scoring vulnerabilities (CVSS) and communicating findings to both technical and non-technical audiences; bug bounty triage or program experience is a strong plus
  • Ability to develop custom testing tools or scripts (Java, Kotlin, C++, Python, or Go)
  • Knowledge of security frameworks and methodologies (OWASP, NIST, BSIMM), threat modeling (STRIDE, DREAD), and system hardening standards (CIS, CSA)
  • Solid understanding of Linux and Windows operating systems, enterprise architecture, and TCP/IP and UDP networking fundamentals
  • Experience testing or exploiting cloud-native applications; understanding cloud security architecture is a plus
  • Strong analytical and problem-solving skills with excellent written and verbal communication; this role communicates directly with external security researchers, engineers, and leadership

About Us 

NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years.

What You'll Love 

  • A collaborative, kind, and curious community
  • Full-time work that is hybrid remote, honoring your flexibility needs
  • A comprehensive benefits package, including medical, dental, and vision insurance
  • A 401(k) plan to help you prepare for your financial future
  • Unlimited PTO that prioritizes your work-life balance
  • Opportunity for growth and advancement

Additional Information 

This position is NOT eligible for Visa sponsorship.

*Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.

Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage, and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington, the base salary hiring range for this position is $130,000 to $165,000 per year.

For roles based in New York, the base salary hiring range for this position is $130,000 to $165,000 per year.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.

 

Similar Jobs

7 Days Ago
In-Office or Remote
United States
120-160 Hourly
Mid level
120-160 Hourly
Mid level
Information Technology • Professional Services • Consulting • Cybersecurity
Conduct web, mobile, API, network, and social engineering penetration tests; identify vulnerabilities, develop technical reports, recommend mitigations, and present findings to clients. Ensure assessments align with GDPR, PCI-DSS, SOC 2, and other standards while tracking emerging threats. The role is remote and contract-based, with cloud security, certifications, mobile testing, API security, and scripting experience preferred.
Top Skills: AWSBashBurp SuiteGCPJavaScriptMetasploitAzureMitre Att&CkNessusNmapOauthOwasp Mobile Security Testing GuideOwasp Top 10PythonWireshark
22 Days Ago
Remote
United States
Senior level
Senior level
Information Technology • Other
Performs application, network, wireless, and enclave penetration testing for a DoD client. Identifies cybersecurity vulnerabilities, develops mitigation strategies, coordinates testing with system owners, and prepares assessment reports and recommendations. The role requires extensive vulnerability assessment experience, knowledge of Windows, Linux, networking, OWASP, PCI DSS, scripting, and penetration testing tools. A DoD Secret clearance and eligibility for IT-I Critical Sensitive or Tier 5 clearance are required.
Top Skills: BashBurp SuiteCanvasIisJavaKismetLinuxMetasploitNessusNmapOwaspPci DssPerlPythonRubyTcp/IpWindows ServerWireless Lan Security
One Month Ago
Remote
USA
Senior level
Senior level
Blockchain • Software
Conduct code audits and penetration tests across AWS cloud environments, infrastructure, backend applications, and blockchain ecosystem tools. Lead red-team exercises, collaborate with detection engineering and incident response teams, develop offensive security automation, support investigations, research emerging threats, and mentor junior staff. The role requires expertise in AWS attack techniques, binary exploitation, web application security, adversary frameworks, and offensive tooling, with Web3 and blockchain security experience preferred.
Top Skills: AsvsAWSBurp SuiteEthereum L1Ethereum L2GoMitre Att&CkNucleiOwasp Top 10PythonSmart Contracts

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account