Securityboat logo
SecurityboatPosted 5 months ago

SecurityBoat RedOps Member (Freelance Pentester)

RemoteIndia

ContractSmall

Job Summary

Execute end-to-end penetration testing on Web, Mobile, API, Cloud, and Active Directory infrastructures, conducting threat modeling and simulating real-world attack scenarios. Document vulnerabilities with clear proof of concept, risk impact, CVSS scores, and actionable remediation steps while maintaining strict confidentiality. Collaborate with internal teams for client debriefs, retests, and knowledge sharing, and stay updated on the latest vulnerabilities and offensive tooling. Engage on short-term freelance projects lasting 5 to 14 days, delivering full availability during standard working hours for assigned scopes.

Required Qualifications

  • Minimum 2+ years of hands-on experience in penetration testing or bug bounty
  • A strong portfolio (CVEs, Hall of Fames, Blogs, or CTF profiles)
  • Availability to work on assigned projects and deliver within given timelines
  • High attention to detail, documentation standards, and ethical conduct
  • Technical Skillset (pick at least 2 core areas)
  • Web & API Pentesting (OWASP Top 10, GraphQL, JWT, SSRF, IDOR, etc.)
  • Mobile Security Testing (Android/iOS – static/dynamic)
  • Network & Infrastructure Pentesting (internal, external, firewall bypass, pivoting)
  • Cloud Security (AWS, Azure, GCP misconfigurations, IAM abuse, etc.)
  • Red Teaming & Adversary Simulation (MITRE ATT&CK, C2, initial access, privilege escalation)
  • Active Directory Pentesting (Kerberoasting, ACL abuse, DCSync, GPO misconfigs, etc.)
  • Ability to perform end-to-end penetration testing on Web, Mobile, APIs, Cloud, Network, and/or Active Directory infrastructures
  • Ability to conduct threat modeling and simulate real-world attack scenarios (manual + tool-based)
  • Ability to document vulnerabilities with clear PoC, risk impact, CVSS scores, and actionable remediation
  • Ability to stay updated with the latest vulnerabilities, attack vectors, and offensive tooling
  • Ability to collaborate with SecurityBoat's internal teams for client debriefs, retests, and knowledge sharing
  • Ability to uphold ethical standards and maintain complete confidentiality of client systems and data
  • Ability to work remotely
  • Ability to get paid competitively for every engagement
  • Ability to be part of an exclusive offensive security community
  • Ability to work on assigned projects and deliver within given timelines
  • Ability to maintain full availability during standard working hours (8 hours/day)
  • Ability to join client calls to clarify findings, discuss technical details, or walk through reports
  • Ability to demonstrate clear communication and professionalism in client interactions
  • Ability to thrive in focused, time-bound projects
  • Ability to handle direct client interactions when needed

Desired Qualifications

  • Offensive Security: OSCP, OSWE, OSEP, OSED
  • PortSwigger: Burp Suite Certified Practitioner
  • eLearnSecurity: eCPPTv2, eWPTXv2, eMAPT
  • Red Team: CRTL, CRTO, CRTP, CRTE
  • Others: CEH, GPEN, GWAPT, PNPT

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce