cover image
Vivid Resourcing

Penetration Tester

Remote

United states

Freelance

16-01-2026

Share this job:

Skills

Communication Penetration Testing Burp Suite Web Testing Security Testing Azure AWS GCP Active Directory

Job Specifications

Senior Penetration Tester (Remote)

1. Roles & Responsibilities

• Conduct hands-on penetration testing across internal networks (Active Directory), external environments, and web/mobile applications.

• Perform cloud penetration tests targeting AWS, Azure, or GCP environments, identifying misconfigurations and exploiting real-world attack paths.

• Operate independently through full engagement cycles: scoping → testing → exploitation → reporting → client communication.

• Deliver high-quality reports using PlexTrac and internal templates, including actionable remediation guidance.

• Present findings to both technical and non-technical stakeholders; maintain strong, professional communication with enterprise clients.

• For senior roles: execute or support wireless assessments, social engineering engagements, and emerging areas such as AI/ML security testing.

• Participate in 3-week testing/reporting cycles and support QA activities across multiple client engagements.

2. Skills (Must-Have & Nice-to-Have)

Must-Have Skills

• Recent (last 12 months) hands-on penetration testing - internal, external, and web application.

• Recent cloud pentesting in AWS, Azure, or GCP (IAM abuse, metadata attacks, misconfigurations, privilege escalation).

• Proficiency with offensive security tools:

o Nmap, BloodHound, Mimikatz, Responder, Impacket

o AWS/Azure/GCP CLI tools, Pacu, cloudhound utilities

o Burp Suite and common web testing tools

• Strong understanding of AD attack paths, lateral movement, escalation techniques, and real exploit execution.

• Ability to produce clear, structured, client-ready penetration testing reports.

• Excellent verbal and written communication with enterprise customers.

Nice-to-Have Skills (Senior-Level)

• Wireless penetration testing (WPA2/WPA3 Enterprise, RADIUS, EAP-TLS, EvilTwin).

• Social engineering experience (phishing, vishing, SMS, onsite).

• AI/ML system or model testing experience.

• Broader red-team or niche offensive security capabilities.

3. Details

• Location: Fully Remote (work from anywhere)

• Start Date: ASAP (ideally by the 1st Jan)

• Work Environment:

o Enterprise clients (internal apps, mobile apps, cloud workloads)

o Heavy emphasis on hands-on testing, reporting, and customer

communication

About the Company

Vivid Resourcing, een toonaangevende internationale partner voor talentoplossingen, brengt u in contact met veelgevraagde technische professionals die u nodig hebt om te floreren in de sectoren Tech, Engineering, Life Sciences en Overheid. Ons wereldwijde bereik is groot, met meer dan 250 specialisten verspreid over 12 Britse, Europese en Amerikaanse kantoren. Al meer dan tien jaar verfijnen we onze unieke aanpak binnen kritieke sectoren. Onze focus op kernsectoren heeft geleid tot een diepgaande kennis en een robuust netwer... Know more