{"id":1539378,"url":"https://alion.io/job/bright-defense-sr-penetration-testing-engineer","title":"Sr Penetration Testing Engineer","company":{"id":1850073,"name":"Bright Defense","domain":"brightdefense.com","url":"https://alion.io/company/brightdefense","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Schema","truth_index":{"grade":"B","score":75,"open_postings":4,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-01T05:45:00Z"}},"role":"QA","role_family":"QA","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"unspecified","remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":74000,"max_usd":164000,"period":"year","method":"global_role_seniority_cell","sample_n":717},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Burp Suite","optional":false},{"name":"CI/CD","optional":false},{"name":"Frida","optional":false},{"name":"GCP","optional":false},{"name":"GraphQL","optional":false},{"name":"HIPAA","optional":false},{"name":"ISO 27001","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Metasploit","optional":false},{"name":"MobSF","optional":false},{"name":"Nmap","optional":false},{"name":"Objection","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"PCI DSS","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"Rest API","optional":false},{"name":"SOC 2","optional":false},{"name":"Threat Modeling","optional":false}],"status":"live","first_seen_at":"2026-09-18T03:22:00Z","employer_posted_date":"2026-09-18","last_verified_at":"2026-10-01T07:17:58Z","board_verified":true,"closed_at":null,"days_open":13,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":13},"description":"Bright Defense · Offensive Security · Now Hiring\nSenior Penetration Tester\nWeb, API & Mobile - Senior Level\nFull-TimeRemoteOffensive SecurityOSCP Required5+ Years Experience\nWe’re looking for a senior tester who owns engagements end to end - scoping, testing, reporting, and retesting - and who has already put AI to work in the testing workflow. You’ll set the quality bar for our testing team and mentor the people coming up behind you.\nAbout Bright Defense\nBright Defense is dedicated to safeguarding our clients’ digital assets by identifying, assessing, and mitigating security vulnerabilities. We partner with a diverse range of customers to keep their web applications, APIs, and mobile apps protected against evolving threats. Our offensive security work feeds directly into the compliance and remediation programs we run for clients across defense, healthcare, fintech, and SaaS.\nKey responsibilities\nCustomer-focused testing\nPlan, execute, and manage penetration tests for Bright Defense customers, focused on web applications and APIs\nConduct manual and automated testing to identify security flaws, misconfigurations, and exploitation paths\nScope engagements and set rules of engagement, timelines, and success criteria with customers\nPerform retesting and validate that fixes actually hold\nQuality assurance & mentorship\nReview and validate reports, findings, and recommendations produced by other testers\nProvide constructive feedback and mentoring to junior and mid-level testers\nMaintain and improve internal testing methodology and deliverable standards\nRemediation & risk\nDeliver clear, actionable remediation strategies customers can execute\nCollaborate with client development teams on secure coding and improved controls\nPerform threat modeling to proactively identify and assess risk\nRecommend countermeasures that measurably reduce threat exposure\nReporting & collaboration\nWrite detailed technical reports and executive summaries for different audiences\nDocument methodologies and findings to support compliance and audit requirements\nWork alongside client project managers, DevOps, and IT security teams\nSupport incident response and post-incident reviews when requested\nAI-assisted testing\nHow we expect you to work\nUse AI to move faster. LLM-assisted recon, payload generation, source code review, and report drafting - with every finding independently validated before it reaches a customer\nTest AI itself. Prompt injection, insecure output handling, and data leakage in LLM-backed customer features\nBuild the workflow. Help develop our internal AI-assisted testing prompts, tooling, and guardrails\n Know the limits. Be ready to talk through where AI sped you up, where it produced garbage, and how you verify its output\nQualifications\nRequired\nOSCP certification\n5+ years in offensive security with hands-on testing of web applications and APIs (REST, GraphQL)\nDemonstrated use of AI tooling as part of the testing workflow\nStrong command of the OWASP Top 10, OWASP API Security Top 10, CWE, and modern authn/authz flaws\nBurp Suite Pro, Metasploit, Nmap, ffuf, and comparable tooling\nScripting in Python, Bash, or PowerShell for custom tooling and exploits\nExcellent written and verbal communication with both engineers and executives\nBachelor’s degree in a related field or equivalent experience\nPreferred\nMobile application testing on iOS and Android - static and dynamic analysis, traffic interception, pinning bypass, insecure local storage, mobile API abuse\nOWASP MASVS/MASTG, Frida, Objection, MobSF\nCloud security in AWS, Azure, or GCP, including privilege escalation paths\nRed team engagements or adversary simulation\nThick client, network, or internal infrastructure testing\nSecurity controls in CI/CD pipelines (DevSecOps)\nBug bounty or responsible disclosure participation\nExposure to SOC 2, ISO 27001, PCI DSS, HIPAA, or CMMC\nRelevant certifications\nOSCP - RequiredOSWEOSWAOSEPGPENGWAPTGMOBCEHCRTOeMAPTeWPTX\nWhy you’ll love this role\nReal variety of targets - web, API, cloud, and mobile - instead of the same engagement on repeat\nFreedom to shape how a growing security firm uses AI in offensive testing, not just permission to try it\nSenior scope from day one: own engagements, set the quality bar, and mentor the testers behind you\nCompensation & perks\nCompetitive base salary - range shared during screening\nRemote-first with flexible working hours\nCertification reimbursement - OSWE, OSEP, GWAPT, GMOB, and more\nDedicated lab time and access to AI tooling for security work\nDirect access to Bright Defense co-founders and leadership\nClient exposure across defense, healthcare, fintech, and SaaS\nHow to apply\nSend your resume, a short note on your testing background, and any relevant work samples - sanitized reports, tooling, CVEs, or bug bounty writeups - to .\nBright Defense is an equal opportunity employer. We build diverse, high-trust teams. | brightdefense.com","description_format":"text","description_chars":4938,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Certification reimbursement","Flexible schedule"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","Information Security","Application Security","Vulnerability Management"],"lifecycle":[{"event":"open","at":"2026-09-30T20:25:24Z"}],"liveness":{"score":17,"band":"cold","label":"Long shot","p_open":1,"p_active":0.385,"p_room":0.45,"age_days":13,"expected_fill_days":7,"reasons":["conf:9","win:tail"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/bright-defense-sr-penetration-testing-engineer","json_url":"https://alion.io/job/bright-defense-sr-penetration-testing-engineer.json","meta":{"generated_at":"2026-10-01T22:08:59Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4878,"day_limit":5000,"remaining_today":122,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}