Penetration Tester - Contract

Other Jobs To Apply

No other job posts for this day.

<p><strong><span data-contrast="auto">Contract Penetration Tester</span></strong><span data-ccp-props="{}"> </span></p> <p><span data-contrast="auto">At Bishop Fox, security isn't just a job—it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation.</span><span data-contrast="auto"> </span><span data-contrast="auto"> </span><span data-ccp-props="{}"> </span></p> <p><span data-contrast="auto">Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions—including 16 open-source tools and 50 security advisories published in the past five years—we're committed to making the digital world safer. </span><span data-ccp-props="{}"> </span></p> <p><span data-contrast="auto">We’re looking for talented, experienced professional hackers to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US and internationally-based teams supporting clients across multiple industries.</span><span data-contrast="auto"> </span><span data-contrast="auto"> </span><span data-contrast="auto"> </span><span data-contrast="auto"> </span><span data-contrast="auto"> </span><span data-ccp-props="{}"> </span></p> <p><strong><span data-contrast="auto">Responsibilities</span></strong><span data-ccp-props="{}"> </span></p> <p><span data-contrast="auto">Bishop Fox is looking for experienced contract penetration testers with a primary focus in web application security and strong secondary expertise in cloud, mobile, source code, network, or AI/LLM security.</span><span data-ccp-props="{}"> </span></p> <p><span data-contrast="auto">You’ll work on a range of projects, from short-term assessments to longer-term program engagements with well-established clients. In this role, you’ll identify vulnerabilities, validate risk, develop creative solutions, and clearly communicate findings and remediation guidance to both technical and executive stakeholders. As a trusted advisor, you’ll help clients understand risk and make informed security decisions. </span><span data-ccp-props="{}"> </span></p> <p><strong><span data-contrast="auto">Experience</span></strong><span data-ccp-props="{}"> </span></p> <ul> <li data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{" 335552541":1,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto"><span data-ccp-parastyle="No Spacing">5+ years of experience planning, conducting, and managing web application penetration tests</span></span> </li> <li data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{" 335552541":1,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><span data-ccp-parastyle="No Spacing">Deep understanding of application security fundamentals, OWASP Top 10, common vulnerabilities, and secure development best practices</span> </li> <li data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{" 335552541":1,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><span data-ccp-parastyle="No Spacing">Experience assessing vulnerabilities and developing exploits across diverse targets</span> </li> <li data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{" 335552541":1,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><span data-ccp-parastyle="No Spacing">Strong understanding of system and network security, authentication protocols, security protocols, and applied cryptography</span> </li> <li data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{" 335552541":1,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><span data-ccp-parastyle="No Spacing">Ability to communicate complex technical findings clearly and </span><span data-ccp-parastyle="No Spacing">provide</span><span data-ccp-parastyle="No Spacing"> practical remediation guidance to technical and executive audiences</span><span data-ccp-props="{" 201341983":0,"335559739":0,"335559740":240}"=""> </span></li> </ul> <p><strong><span data-contrast="auto">Preferred Experience</span></strong><span data-ccp-props="{}"> </span></p> <p><span data-contrast="auto">Deep experience in at least one of the following:</span><span data-ccp-props="{}"> </span></p> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{" 335552541":1,"335559685":360,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing">Cloud Security</span></span></strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing"> - Experience assessing AWS cloud environments, including technologies such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambda.</span></span><span data-ccp-props="{" 201341983":0,"335559739":0,"335559740":240}"=""> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{" 335552541":1,"335559685":360,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="2" data-aria-level="1"><strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing">Mobile Application Security</span></span></strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing"> - Experience testing iOS and/or Android applications, including mobile application architecture, API communication, data storage, authentication flows, and common mobile security vulnerabilities.</span></span><span data-ccp-props="{" 201341983":0,"335559739":0,"335559740":240}"=""> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{" 335552541":1,"335559685":360,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="3" data-aria-level="1"><strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing">Source Assisted</span><span data-ccp-parastyle="No Spacing"> Application Assessments: </span></span></strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing">Experience evaluating applications across multiple layers, including source code, APIs, infrastructure, and integrations. Strong </span><span data-ccp-parastyle="No Spacing">proficiency</span><span data-ccp-parastyle="No Spacing"> in Golang is highly preferred, along with familiarity in languages such as Python, Ruby, PowerShell, Java, and JavaScript.</span></span><span data-ccp-props="{" 201341983":0,"335559739":0,"335559740":240}"=""> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{" 335552541":1,"335559685":360,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="4" data-aria-level="1"><strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing">Network Security</span></span></strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing"> - Experience with network and system exploitation, including modern tactics, techniques, and procedures such as C2 frameworks, EDR bypass, privilege escalation, password cracking, and lateral movement.</span></span><span data-ccp-props="{" 201341983":0,"335559739":0,"335559740":240}"=""> </span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{" 335552541":1,"335559685":360,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="5" data-aria-level="1"><strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing">AI/LLM Security</span></span></strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing"> -</span></span><strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing"> </span></span></strong><span data-contrast="auto"><span data-ccp-parastyle="No Spacing">Experience assessing </span><span data-ccp-parastyle="No Spacing">non-deterministic security controls.</span></span><span data-ccp-props="{" 201341983":0,"335559739":0,"335559740":240}"=""> </span></li> </ul> <p><span data-teams="true"><strong>Employment Sponsorship</strong></span></p> <p><span data-teams="true">This engagement is for independent contractors (1099) and <strong>is not eligible for any form of employment sponsorship.</strong> Applicants must be legally authorized to work in the United States without requiring visa sponsorship now or in the future. Applicants must be located in the United States. </span></p> <p><span data-teams="true"><span data-contrast="auto">All new hires must pass a background check as a condition of employment.</span><span data-ccp-props="{}"> </span></span></p> <p><em><span data-contrast="auto">Bishop Fox is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.</span><span data-ccp-props="{}"> </span></em></p> <p><span data-ccp-props="{}"> </span></p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...