SecurityBoat RedOps Member (Freelance Pentester)
RemoteIndia
Job Summary
Execute end-to-end penetration testing on Web, Mobile, API, Cloud, and Active Directory infrastructures, conducting threat modeling and simulating real-world attack scenarios. Document vulnerabilities with clear proof of concept, risk impact, CVSS scores, and actionable remediation steps while maintaining strict confidentiality. Collaborate with internal teams for client debriefs, retests, and knowledge sharing, and stay updated on the latest vulnerabilities and offensive tooling. Engage on short-term freelance projects lasting 5 to 14 days, delivering full availability during standard working hours for assigned scopes.
Required Qualifications
- Minimum 2+ years of hands-on experience in penetration testing or bug bounty
- A strong portfolio (CVEs, Hall of Fames, Blogs, or CTF profiles)
- Availability to work on assigned projects and deliver within given timelines
- High attention to detail, documentation standards, and ethical conduct
- Technical Skillset (pick at least 2 core areas)
- Web & API Pentesting (OWASP Top 10, GraphQL, JWT, SSRF, IDOR, etc.)
- Mobile Security Testing (Android/iOS – static/dynamic)
- Network & Infrastructure Pentesting (internal, external, firewall bypass, pivoting)
- Cloud Security (AWS, Azure, GCP misconfigurations, IAM abuse, etc.)
- Red Teaming & Adversary Simulation (MITRE ATT&CK, C2, initial access, privilege escalation)
- Active Directory Pentesting (Kerberoasting, ACL abuse, DCSync, GPO misconfigs, etc.)
- Ability to perform end-to-end penetration testing on Web, Mobile, APIs, Cloud, Network, and/or Active Directory infrastructures
- Ability to conduct threat modeling and simulate real-world attack scenarios (manual + tool-based)
- Ability to document vulnerabilities with clear PoC, risk impact, CVSS scores, and actionable remediation
- Ability to stay updated with the latest vulnerabilities, attack vectors, and offensive tooling
- Ability to collaborate with SecurityBoat's internal teams for client debriefs, retests, and knowledge sharing
- Ability to uphold ethical standards and maintain complete confidentiality of client systems and data
- Ability to work remotely
- Ability to get paid competitively for every engagement
- Ability to be part of an exclusive offensive security community
- Ability to work on assigned projects and deliver within given timelines
- Ability to maintain full availability during standard working hours (8 hours/day)
- Ability to join client calls to clarify findings, discuss technical details, or walk through reports
- Ability to demonstrate clear communication and professionalism in client interactions
- Ability to thrive in focused, time-bound projects
- Ability to handle direct client interactions when needed
Desired Qualifications
- Offensive Security: OSCP, OSWE, OSEP, OSED
- PortSwigger: Burp Suite Certified Practitioner
- eLearnSecurity: eCPPTv2, eWPTXv2, eMAPT
- Red Team: CRTL, CRTO, CRTP, CRTE
- Others: CEH, GPEN, GWAPT, PNPT
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.