Penetration Tester
HybridAlbuquerque, New Mexico, United States
Job Summary
Conduct comprehensive penetration testing and vulnerability assessments on computer systems, networks, and applications using manual techniques, automated tools, and the MITRE ATT&CK framework. Develop prototype tools for security data analytics and assist in red teaming exercises to simulate real-world attack scenarios. Execute detailed test plans, collaborate with cross-functional teams on remediation strategies, and perform system hardening reviews. Manage project timelines, interact with clients to deliver findings, and prepare reports documenting identified issues. Research emerging security topics, assist developers on secure coding practices, and integrate GenAI tools into daily workflows for automation and analysis.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience)
- At least 2-5 years of experience in penetration testing and vulnerability assessments, with a focus on web applications, networks, and infrastructure
- Experienced with programming/scripting languages (e.g.: Python, Bash, Rust)
- In-depth knowledge of various penetration testing tools, frameworks and OS (e.g., Kali Linux, Metasploit, Burp Suite, Nmap, Wireshark, etc.)
- Good understanding of common vulnerabilities and attack vectors (e.g., SQL injection, cross-site scripting, buffer overflows, etc.) and corresponding mitigation techniques
- Familiarity with industry standards and frameworks such as OWASP top 10, CVE, CWE, SANS, OSSTMM, and NIST
- Excellent analytical and problem-solving skills, with the ability to think creatively and strategically to find vulnerabilities
- Effective communication and presentation skills to convey complex technical concepts to both technical and non-technical stakeholders
- Demonstrated ability to use GenAI tools (e.g., Claude, ChatGPT, etc.) for daily work - drafting, research, summarization, data analysis, code generation, or workflow automation as relevant to the role
- Working knowledge of GenAI limitations including hallucination risk, context window constraints, and data sensitivity boundaries; ability to validate AI-generated output before acting on it
- Familiarity with prompt engineering techniques - structuring multi-step instructions, providing context, and iterating on output quality to achieve production-grade results
- Comfort with agentic AI workflows - using, designing, or building multi-step AI agents that execute tasks autonomously with human-in-the-loop validation
- Awareness of AI security fundamentals - prompt injection risks, data classification rules, sandboxed execution, and responsible handling of sensitive data in AI workflows
- Familiarity with connecting GenAI tools to internal data sources, APIs, and enterprise systems
- Ability to contribute reusable AI skills, templates, agent configurations, or automation workflows to a shared repository for team-wide use
- Willingness to learn and adopt new AI tools as they evolve; participation in AI adoption sprints, hackathons, and knowledge-sharing within the team
- Having proficient knowledge in MITRE ATT&CK framework
Desired Qualifications
- GIAC, OSCP, OSEP, HTB Certifications, CEH, CompTIA Pentest+, CRTP, CRTE or any equivalent security certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.