Associate Penetration Tester
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Associate Penetration Tester conducting network, application, and social engineering tests for FRSecure, an information security consultancy. Documenting vulnerabilities and advising clients on remediation.
Responsibilities:
- Provide security posture validation through penetration testing of systems on client networks
- Execute external penetration tests, including reconnaissance, enumeration of internet-facing systems and services, vulnerability identification, reporting, and client delivery
- Conduct internal penetration tests of client networks
- Perform application penetration tests of client applications
- Execute social engineering tests, including reconnaissance, campaign pretext design, phishing emails, spoofed logon forms, reporting, and client delivery
- Lead vulnerability assessments and remediation consulting
- Perform vulnerability scans, generate scan reports, and advise on remediation
- Document testing methodologies, technical findings, proof-of-concept evidence, attack chains, and business impact in professional reports
- Stay current on emerging threats, attack techniques, tools, and industry trends through research, training, certifications, lab work, and knowledge sharing
- Maintain compliance with internal quality standards, client confidentiality requirements, and OWASP, PTES, NIST, and MITRE ATT&CK frameworks and methodologies
- Review colleagues’ reports for formatting and narrative errors and provide feedback
- Work alongside experienced security consultants
- Periodically work outside standard hours to accommodate United States client time zones
- Occasionally travel for on-site client visits, projects, and team or company activities
Requirements:
- Associates degree in related field required, or equivalent combination of education, certification and experience
- Minimum of 1-2 years of experience managing IT systems in a professional environment required
- CEH, Net+ or similar IT or security industry recognized certification preferred
- General knowledge of Networks, Linux systems, Windows systems, web applications, and scripting languages
- Familiarity with common attack tools, concepts, and frameworks used for reconnaissance, enumeration, vulnerability identification, exploitation, and reporting
- Excellent verbal and written communication skills
- Ability to clearly document technical findings, develop client-ready deliverables, and present complex information professionally
- Demonstrated commitment to exceptional customer service and effective client relationship management
- Ability to translate technical security concepts, risks, and remediation recommendations for business stakeholders and non-technical audiences
- Strong analytical and critical-thinking skills
- Ability to evaluate security weaknesses, validate findings, and recommend practical risk mitigation strategies
- Effective organizational and time management skills
- Ability to manage multiple projects and competing deadlines while maintaining attention to detail
- Proficient with all Microsoft Office Suite products
- Must be located in one of the specified United States states
Benefits:
- Flexible schedules and remote or hybrid work options
- Employee Assistance Program (EAP)
- Mental wellbeing support
- Ongoing learning opportunities and professional development support
- Medical, dental and vision insurance
- Health savings, flexible savings and dependent care savings account options
- Life and disability insurance
- 401(k) with employer match up to 4%
- Pet insurance
- Unlimited paid time off
- Paid parental leave: 6 weeks for non-birthing parents and 12 weeks for birthing parents at 100% regular, straight time weekly pay
- 11 paid holidays
- Volunteer time off
- Flexible working schedule outside scheduled meetings
- Minimal travel, less than 5%

















