远程工作雷达

渗透测试员 - 基础设施与红队 (德克萨斯/佛罗里达)

Penetration Tester - Infrastructure & Red Team (Texas/Florida)

开发工程限定地区(需当地身份)
公司Packetlabs Ltd.
薪资$90,000 - $130,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

Packetlabs是由一位道德黑客在看到将漏洞评估误称为渗透测试的情况后创建的。我们的标语“在风险成为头条新闻前识别风险”体现了不给客户错误安全感的重要性。

我们是一支充满热情、训练有素、积极主动的道德黑客团队。我们提供专业级别的渗透测试服务,全面且定制化,以帮助建立一个每个人都有权享受隐私和安全的数字空间。Packetlabs的顾问会发现其他人忽略的弱点,并不断学习新的绕过控制的方法。我们对自己有着极高的标准。

为此,我们只雇佣具有相同热情和动力的人。

道德黑客——基础设施与红队负责规划、执行和报告基础设施渗透测试、云安全评估、Active Directory安全评估以及对手模拟活动。该职位通过使用行业认可的进攻性安全方法,在企业基础设施中识别、验证并演示可利用的安全漏洞,来评估客户安全控制的有效性。

该职位独立工作并与其它安全顾问协作,对本地、混合和云环境进行进攻性安全评估,同时参与红队操作、紫队演练和高级安全测试活动。该职位通过详细的报告和演示向客户提供技术指导,同时为Packetlabs进攻性安全方法、工具和产品服务的持续改进做出贡献。

我们寻找以下人员

  • 计算机科学、网络安全、信息技术或相关专业的学士学位;同等的实际经验将被考虑。
  • 至少3年从事基础设施渗透测试、红队操作、对手模拟或进攻性安全咨询的专业经验。
  • 在企业基础设施上进行渗透测试的经验,包括Windows、Linux、Active Directory、Microsoft Entra ID、云平台和企业网络。
  • 进行内部和外部网络渗透测试、权限提升、Active Directory安全评估和横向移动测试的经验。
  • 评估云环境的经验,包括AWS、Micr
查看英文原文

Packetlabs was built by an ethical hacker after seeing vulnerability assessments presented as penetration tests. Our slogan "Identify Risks Before They Become Headlines" drives at the importance of not providing our clients with a false sense of security.

We are a passionate team of highly trained, proactive ethical hackers. We provide expert-level penetration testing services that are thorough and tailored to help foster a safe digital space where everyone has the right to privacy and security. Packetlabs consultants find weaknesses others overlook and continuously learn new ways to evade controls. We hold ourselves to a very high standard.

To do so, weonlyhire individuals with the same drive and passion.

The Ethical Hacker – Infrastructure & Red Team is responsible for planning, executing, and reporting on infrastructure penetration testing, cloud security assessments, Active Directory security assessments, and adversary simulation engagements. The role evaluates the effectiveness of client security controls by identifying, validating, and demonstrating exploitable security vulnerabilities across enterprise infrastructure using industry-recognized offensive security methodologies.

Working independently and collaboratively with other security consultants, the Ethical Hacker performs offensive security assessments across on-premises, hybrid, and cloud environments while contributing to red team operations, purple team exercises, and advanced security testing engagements. The role provides technical guidance to clients through detailed reporting and presentations while contributing to the continuous improvement of Packetlabs' offensive security methodologies, tooling, and service offerings.

Who we are looking for

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline; equivalent practical experience will be considered.
  • Minimum of 3 years of professional experience performing infrastructure penetration testing, red teaming, adversary simulation, or offensive security consulting.
  • Demonstrated experience conducting penetration testing across enterprise infrastructure, including Windows, Linux, Active Directory, Microsoft Entra ID, cloud platforms, and enterprise networking.
  • Experience performing internal and external network penetration testing, privilege escalation, Active Directory security assessments, and lateral movement testing.
  • Experience assessing cloud environments, including AWS, Microsoft Azure, or Google Cloud Platform.
  • Strong understanding of enterprise networking, authentication technologies, identity management, cloud security, and offensive security methodologies.
  • Experience using industry-standard offensive security frameworks, tools, and tradecraft.
  • Excellent technical writing, presentation, and communication skills, with the ability to communicate findings to both technical and executive stakeholders.
  • Industry certifications such as OSCP, OSEP, CRTO, CRTE, CARTP, CARTA, CREST CRT, CREST CCT, PNPT, GPEN, GXPN, or equivalent are considered an asset. OSCP or equivalent demonstrated technical capability is strongly preferred.
  • Experience participating in Red Team, Purple Team, adversary simulation, or threat emulation engagements is considered an asset.
  • Customer-first mentality. You are a great communicator with clients, project managers, and teammates. Rapid responses and on time.
  • You deliver work that you take pride in. Your work is an autograph of your excellence.
  • You dig deeper into every finding. Doesn't stop until impact is proven.
  • You are comfortable being uncomfortable. Goes towards obstacles, not away from them. Consulting isn't your typical job and requires adapting to rapidly changing environments.
  • You are always learning. Cybersecurity is changing every day, and you need to keep up or want to keep up. Be deeply aware of your skillset and be willing to improve.
  • You are self-motivated and dependable.
  • You are humble. Egos don't have a place at Packetlabs.

What you’ll be doing

  • Infrastructure Security Assessments
  • Plan and execute infrastructure penetration testing engagements across on-premises, hybrid, cloud, wireless, and enterprise network environments.
  • Perform internal and external network penetration testing to identify, validate, and exploit security vulnerabilities using manual testing methodologies and industry-standard offensive security tools.
  • Assess enterprise technologies including Active Directory, Microsoft Entra ID (Azure AD), Windows and Linux environments, virtualization platforms, cloud services, and supporting infrastructure.
  • Evaluate cloud environments including AWS, Microsoft Azure, and Google Cloud Platform to identify configuration weaknesses, privilege escalation opportunities, identity risks, and cloud security vulnerabilities.
  • Assess containerized environments, Kubernetes platforms, CI/CD pipelines, and cloud-native technologies where applicable.
  • Red Team & Adversary Simulation
  • Participate in and lead adversary simulation, red team, and objective-based security engagements in accordance with established methodologies and client objectives.
  • Execute offensive security operations across the attack lifecycle, including reconnaissance, initial access, persistence, privilege escalation, credential access, lateral movement, defense evasion, command and control, and objective execution.
  • Support purple team engagements by working collaboratively with defensive teams to validate detections, improve monitoring capabilities, and strengthen defensive controls.
  • Develop and execute attack scenarios that demonstrate realistic business impact while maintaining client system integrity.
  • Client Delivery & Reporting
  • Prepare comprehensive technical reports that clearly communicate vulnerabilities, attack paths, business impact, risk ratings, and remediation recommendations.
  • Present assessment findings to technical teams, executive stakeholders, and client leadership.
  • Provide technical guidance on remediation strategies, security architecture, and defensive improvements.
  • Manage assigned engagements while ensuring delivery quality, timelines, and client expectations are achieved.
  • Technical Leadership & Continuous Improvement
  • Maintain expertise in offensive security methodologies, infrastructure security, cloud technologies, Active Directory security, and emerging attack techniques.
  • Contribute to the development and continuous improvement of testing methodologies, internal tooling, technical documentation, and service offerings.
  • Participate in technical research, automation initiatives, internal training, and knowledge-sharing activities.
  • Collaborate with consulting teams to strengthen technical quality, consistency, and service delivery across the Offensive Security practice.
  • Perform other duties as assigned.

How is success defined

  • Performance in this role is evaluated using a combination of technical, operational, and client-focused measures, including but not limited to:
  • Successful delivery of infrastructure penetration testing and adversary simulation engagements within established quality, budget, and timeline expectations.
  • Accuracy, completeness, and technical quality of client reports and deliverables.
  • Demonstrated expertise across enterprise infrastructure, cloud security, Active Directory, and offensive security methodologies.
  • Positive client feedback regarding technical expertise, communication, and professionalism.
  • Contribution to technical research, methodology development, automation, and knowledge-sharing initiatives.
  • Effective collaboration with Delivery Managers, Project Managers, and consulting team members.
  • Ongoing professional development through certifications, research, and technical skill advancement.

Why us?

  • A leadership team that values substance, quality, and disciplined execution
  • Collaboration with a highly skilled team of security professionals who are passionate about technical excellence and raising the bar
  • Competitive compensation and growth opportunity
  • Paid education and professional development reimbursement to support continued learning, certifications and technical growth
  • Flexible work environment that empowers employees to do their best work
  • Paid volunteer day each year to give back to your community
  • Paid Birthday day off
  • Paid U.S. public holidays
  • Fully remote within Texas or Florida

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位