728,487open jobs
43,495companies
102,978added this week
Browse all
Location
Remote (North America)

Confirmed on the employer's own hiring board on Sep 23, 2026. First seen by Alion on Jan 16, 2026. Sprocket Security scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Sprocket Security was founded to improve the way we approach cybersecurity. Currently the industry performs services in a timeboxed, or point-in-time approach. We think this is fundamentally flawed.

Penetration Tester 

Location: Remote - North America

Company Mission - Our mission is to help secure as many companies as possible, by using the best way of doing so: penetration testing. Sprocket Security prioritizes offensive security for enterprises, empowering them to build robust defense strategies based on individual business risk.

How - At Sprocket Security, we've built an expert-driven Continuous Penetration Testing platform that blends cutting-edge automated and manual testing methods.

Your Mission - The easy work is disappearing, and we built it that way on purpose. Our platform now owns the recon, the scanning, the first pass anyone could run, so you start each day with leads already surfaced instead of a blank terminal. Your job is everything the tooling can't do: chasing a lead into a critical finding, going back into the same network a third time because you know there's more in it, and being the human a client trusts when the report lands.

Responsibilities:

  • Own continuous testing across your clients' full attack surfaces (network, web app, cloud, social engineering) by conducting manual penetration testing and directing automation and agents rather than running one-off scoped projects.
  • Take raw leads the platform surfaces and push them into deep, chained, business-level impact, including post-exploitation, lateral movement, and privilege escalation.
  • Validate whether activity was detected and acted on, not just whether you got in, and call out where a client's defenses held.
  • Write clear, business-relevant attack narratives that explain impact to technical and non-technical audiences.
  • Run debriefs and client conversations that build trust and position Sprocket as a partner, not a vendor.
  • Feed repeatable techniques and automation candidates back to R&D so a one-off discovery becomes a capability the whole team runs continuously.
  • Mentor junior testers and interns, stay reachable, and think out loud with your team rather than working in silence.
  • Build scripts and tooling to improve your own efficiency and the team's.

Requirements:

Minimum

  • Web application testing beyond OWASP Top 10 basics: auth flaws, business logic, injection at depth.
  • Network and Active Directory testing: lateral movement, privilege escalation, not just scan-and-report.
  • Comfort directing, supervising, and validating AI and automation tooling across the full autonomy spectrum, and pushing well past what it surfaces on its own.
  • Post-exploitation and impact demonstration, with the ability to translate a technical finding into what it means for a specific client's business.
  • Scripting ability (Python, Bash, or equivalent) with a track record of building tools to improve efficiency.
  • Client-facing experience delivering findings and handling technical and non-technical conversations.
  • Genuine comfort with ambiguity and a role whose center of gravity keeps shifting toward harder, less routine work.
  • A collaborative approach: you ask early, share often, and invest in the people around you.

Preferred

  • OSCP or equivalent hands-on certification.
  • OSWE, CRTO, GPEN, GWAPT, or cloud security certifications (AWS Security Specialty, AZ-500).
  • Published research, disclosed CVEs, or an active bug bounty profile.

Certifications & Education: No specific degree or certification required. Equivalent hands-on experience is valued equally or more. If OSCP or equivalent isn't already held, we expect it within roughly 12 months, and we support that with a training budget.

This Role Might Not Be For You If:

  • You want a role built around one-time scoped engagements rather than continuous testing across a client's full surface.
  • You see AI and automation tooling as a threat to the craft rather than something that multiplies your reach.
  • You'd rather work heads-down than think out loud, ask for help, or hand off what you find to teammates and R&D.
  • You want the day-to-day to stay the same over time. This role's center of gravity keeps moving toward harder, stranger, more interesting ground, and that's the deal, not a catch.

Benefits:

  • Unlimited and mandatory PTO for healthy work/life balance.
  • Company matched 401k (immediate eligibility, no one should have to wait to start saving).
  • 75% company contribution for health insurance for employees and 50% for dependants.
  • 100% company contribution for dental and vision.
  • Flexible working hours.
  • Hardware and tools of your choice
  • Support for your career development with paid training, conferences, certifications, etc.

Location: Remote

Ready to Trailblaze the Cybersecurity Frontier? If you're passionate about cybersecurity and eager to make an impact in the industry, we want you on our team. Apply now at Sprocket Security and join the revolution of safeguarding businesses from cyber threats!

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
728,487 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$122k – $209k per year • Remote/Hybrid • Full-Time • 8+ years exp • Owings Mills
DevOps
AWS
IAM
DNS
Cybersecurity
Zero Trust
Least Privilege
Microsoft Entra ID
Active Directory
LDAP
PKI
Apply
$76k – $110k per year • In office • Confidential • Full-Time • 2+ years exp • Bachelor's Degree • Austin
DevOps
GCP
Azure
Windows Server
AWS
Kubernetes
Linux
Windows
VPN
Cybersecurity
Least Privilege
Active Directory
SIEM
Management
ServiceNow
Apply
$197k – $225k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • McLean
Python
Java
SQL
Scala
Databases
Snowflake
Databricks
Cassandra
DynamoDB
Amazon Redshift
AI/ML
Spark
Dagster
Machine Learning
DevOps
Splunk
GCP
Azure
AWS
Management
Agile
Apply
$286k – $327k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • San Francisco • McLean • Richmond • Chicago • New York
Python
Go
JavaScript
Rust
TypeScript
C#
Scala
AI/ML
AI Agents
Machine Learning
DevOps
GCP
Azure
AWS
HPC
Apply
$137k – $268k per year • Remote/Hybrid • Full-Time • PhD • London
Python
C++
C++
PyTorch C++
AI/ML
CUDA Toolkit
Diffusion Models
Computer Vision
PyTorch
Gaussian Splatting
CUDA
Physical AI
Embodied AI
Machine Learning
Robotics
Sim-to-Real
Management
Google Maps
Apply
$53k – $128k per year (Estimated) • In office • Madison
AI/ML
Claude
DevOps
DNS
Cybersecurity
NIST CSF
PCI DSS
HIPAA
OWASP
Apply
Remote • Bachelor's Degree • Madison
Apply
$84k – $183k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Central
Assembly
DevOps
Linux
DNS
Cybersecurity
NIST CSF
PCI DSS
HIPAA
OWASP
Apply
In office • Bachelor's Degree • Madison
Marketing
LinkedIn
Apply
In office • Bachelor's Degree • Madison
Apply
See all jobs
This is one of many
728,487 more open roles from verified company boards, updated every day.