Bishop Fox Logo

Bishop Fox

Penetration Tester

Reposted One Month Ago
Be an Early Applicant
Remote
Hiring Remotely in U.S.
Senior level
Remote
Hiring Remotely in U.S.
Senior level
As a Penetration Tester at Bishop Fox, you'll perform security assessments on applications and networks, advise clients, and solve technical challenges.
The summary above was generated by AI

At Bishop Fox, security isn't just a job—it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation.  

Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions—including 16 open-source tools and 50 security advisories published in the past five years—we're committed to making the digital world safer. 

We’re looking for talented, experienced professional hackers to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US and internationally-based teams supporting clients across multiple industries.                                                    

Responsibilities 

You’re a penetration tester who knows their way around source code. You’ve plundered apps and pillaged networks (legally, of course). You have a passion for hacking and information security. You may also have written a few blog posts about your favorite hacks or have presented at a handful of conferences – with an eye to doing more. 

With Bishop Fox, your responsibilities would include testing web applications, hacking networks, and reversing software. As a consultant, you’ll work on a variety of projects which include short-term engagements and extended program work with well-established clients. You'll solve challenging technical problems and build creative solutions. As a trusted advisor, you’ll provide your expert opinion to help our clients navigate difficult business decisions.         

Requirements 

  • 4+ years experience in planning, conducting, and managing web application penetration tests
  • 5+ years of application security experience
  • Deep understanding of security fundamentals (OWASP), common vulnerabilities, and application security best practices
  • Skilled in vulnerability assessment and the development of exploits for diverse targets
  • Background in system and network security, authentication and security protocols, and applied cryptography is helpful
  • Experience with programming and scripting languages such as Python, Ruby, PowerShell, Java, JavaScript, etc.
  • Bonus if you have experience reviewing Golang source code for vulnerabilities
  • Proficiency with operating systems- Linux, Windows, MacOS
  • Experience with network and system exploitation including modern tactics, techniques, and procedures (e.g. c2 frameworks, EDR bypass, privilege escalation, password cracking, lateral movement, etc.)
  • Strong technical reporting and documentation skills
  • Advanced relevant academic training, such as a degree in Computer Science or an OSCP, is a definite bonus
  • Experience with AWS cloud environments preferred with an understanding of its major technologies, such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambdas, and how to keep them secure
  • Secondary expertise in one or more of the following areas preferred: Cloud Security Assessments, Mobile Application Security Testing, Hybrid Application Assessments, or AI/LLM Security Assessments. Ability to communicate technical findings clearly to both technical and executive stakeholders, including actionable remediation guidance. 

Bishop Fox has always allowed its employees to work remotely, and this role could work anywhere in the United States. Our comprehensive benefits program is tailored to meet your needs at an affordable price. We embrace diversity and an inclusive culture. We value our employees and who they are, which fosters a powerful and collective talent base to successfully serve our clients and the security community with unparalleled expertise.  

Bishop Fox is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.  All new hires must pass a background check as a condition of employment. 

Interested? Apply today!    

Similar Jobs

Yesterday
Remote
United States
Senior level
Senior level
Information Technology • Other
Performs application, network, wireless, and enclave penetration testing for a DoD client. Identifies cybersecurity vulnerabilities, develops mitigation strategies, coordinates testing with system owners, and prepares assessment reports and recommendations. The role requires extensive vulnerability assessment experience, knowledge of Windows, Linux, networking, OWASP, PCI DSS, scripting, and penetration testing tools. A DoD Secret clearance and eligibility for IT-I Critical Sensitive or Tier 5 clearance are required.
Top Skills: BashBurp SuiteCanvasIisJavaKismetLinuxMetasploitNessusNmapOwaspPci DssPerlPythonRubyTcp/IpWindows ServerWireless Lan Security
6 Days Ago
In-Office or Remote
90K-190K Annually
Senior level
90K-190K Annually
Senior level
Information Technology • Consulting • Defense
Leads penetration-testing engagements across networks, applications, cloud, identity systems, and exposed assets. Owns scoping, rules of engagement, planning, execution, evidence validation, vulnerability prioritization, reporting, customer briefings, remediation clarification, and quality review. Mentors junior testers while conducting hands-on testing involving privilege escalation, lateral movement, pivoting, and controlled exploitation. Supports federal CDM cybersecurity assessments and escalates safety, scope, and material findings.
Top Skills: Active DirectoryAd CsAWSAzureBloodhoundBurp Suite ProCertifyCertipyCisa KevCvssImpacketKubernetesLinuxMetasploitNessusNetexecNmapOwasp ZapPowerviewTcpdumpTenableWindowsWireshark
9 Days Ago
Remote
USA
Senior level
Senior level
Blockchain • Software
Conduct code audits and penetration tests across AWS cloud environments, infrastructure, backend applications, and blockchain ecosystem tools. Lead red-team exercises, collaborate with detection engineering and incident response teams, develop offensive security automation, support investigations, research emerging threats, and mentor junior staff. The role requires expertise in AWS attack techniques, binary exploitation, web application security, adversary frameworks, and offensive tooling, with Web3 and blockchain security experience preferred.
Top Skills: AsvsAWSBurp SuiteEthereum L1Ethereum L2GoMitre Att&CkNucleiOwasp Top 10PythonSmart Contracts

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account