{"id":951956,"url":"https://alion.io/job/sprocket-security-penetration-tester","title":"Penetration Tester","company":{"id":684916,"name":"Sprocket Security","domain":"sprocketsecurity.com","url":"https://alion.io/company/sprocketsecurity","size_band":null,"is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":75,"open_postings":5,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-24T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":null,"employment_type":null,"work_mode":"remote","remote_scope":"stated_regions","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":["US","CA","MX","AG","AW","BS","BB","BZ","BM","VG","BQ","KY","CR","CW","DM","DO","SV","GL","GD","GP","GT","HT","HN","JM","MQ","MS","NI","PA","PR","KN","LC","PM","SX","TT","TC","VI"],"hiring_countries_total":36,"salary":null,"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false}],"status":"live","first_seen_at":"2026-01-16T09:28:43Z","employer_posted_date":"2026-08-03","last_verified_at":"2026-09-23T22:04:12Z","board_verified":true,"closed_at":null,"days_open":251,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":250},"description":"Penetration Tester \nLocation: Remote - North America\nCompany Mission - Our mission is to help secure as many companies as possible, by using the best way of doing so: penetration testing. Sprocket Security prioritizes offensive security for enterprises, empowering them to build robust defense strategies based on individual business risk.\nHow - At Sprocket Security, we've built an expert-driven Continuous Penetration Testing platform that blends cutting-edge automated and manual testing methods.\nYour Mission - The easy work is disappearing, and we built it that way on purpose. Our platform now owns the recon, the scanning, the first pass anyone could run, so you start each day with leads already surfaced instead of a blank terminal. Your job is everything the tooling can't do: chasing a lead into a critical finding, going back into the same network a third time because you know there's more in it, and being the human a client trusts when the report lands.\nResponsibilities:\nOwn continuous testing across your clients' full attack surfaces (network, web app, cloud, social engineering) by conducting manual penetration testing and directing automation and agents rather than running one-off scoped projects.\nTake raw leads the platform surfaces and push them into deep, chained, business-level impact, including post-exploitation, lateral movement, and privilege escalation.\nValidate whether activity was detected and acted on, not just whether you got in, and call out where a client's defenses held.\nWrite clear, business-relevant attack narratives that explain impact to technical and non-technical audiences.\nRun debriefs and client conversations that build trust and position Sprocket as a partner, not a vendor.\nFeed repeatable techniques and automation candidates back to R&D so a one-off discovery becomes a capability the whole team runs continuously.\nMentor junior testers and interns, stay reachable, and think out loud with your team rather than working in silence.\nBuild scripts and tooling to improve your own efficiency and the team's.\nRequirements:\nMinimum\nWeb application testing beyond OWASP Top 10 basics: auth flaws, business logic, injection at depth.\nNetwork and Active Directory testing: lateral movement, privilege escalation, not just scan-and-report.\nComfort directing, supervising, and validating AI and automation tooling across the full autonomy spectrum, and pushing well past what it surfaces on its own.\nPost-exploitation and impact demonstration, with the ability to translate a technical finding into what it means for a specific client's business.\nScripting ability (Python, Bash, or equivalent) with a track record of building tools to improve efficiency.\nClient-facing experience delivering findings and handling technical and non-technical conversations.\nGenuine comfort with ambiguity and a role whose center of gravity keeps shifting toward harder, less routine work.\nA collaborative approach: you ask early, share often, and invest in the people around you.\nPreferred\nOSCP or equivalent hands-on certification.\nOSWE, CRTO, GPEN, GWAPT, or cloud security certifications (AWS Security Specialty, AZ-500).\nPublished research, disclosed CVEs, or an active bug bounty profile.\nCertifications & Education: No specific degree or certification required. Equivalent hands-on experience is valued equally or more. If OSCP or equivalent isn't already held, we expect it within roughly 12 months, and we support that with a training budget.\nThis Role Might Not Be For You If:\nYou want a role built around one-time scoped engagements rather than continuous testing across a client's full surface.\nYou see AI and automation tooling as a threat to the craft rather than something that multiplies your reach.\nYou'd rather work heads-down than think out loud, ask for help, or hand off what you find to teammates and R&D.\nYou want the day-to-day to stay the same over time. This role's center of gravity keeps moving toward harder, stranger, more interesting ground, and that's the deal, not a catch.\nBenefits:\nUnlimited and mandatory PTO for healthy work/life balance.\nCompany matched 401k (immediate eligibility, no one should have to wait to start saving).\n75% company contribution for health insurance for employees and 50% for dependants.\n100% company contribution for dental and vision.\nFlexible working hours.\nHardware and tools of your choice\nSupport for your career development with paid training, conferences, certifications, etc.\nLocation: Remote\nReady to Trailblaze the Cybersecurity Frontier? If you're passionate about cybersecurity and eager to make an impact in the industry, we want you on our team. Apply now at Sprocket Security and join the revolution of safeguarding businesses from cyber threats!","description_format":"text","description_chars":4754,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["401k plan","Flexible schedule","Health insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"region"},{"name":"Canada","iso":"CA","kind":"region"},{"name":"Mexico","iso":"MX","kind":"region"},{"name":"Anguilla","iso":null,"kind":"region"},{"name":"Antigua and Barbuda","iso":"AG","kind":"region"},{"name":"Aruba","iso":"AW","kind":"region"},{"name":"Bahamas","iso":"BS","kind":"region"},{"name":"Barbados","iso":"BB","kind":"region"},{"name":"Belize","iso":"BZ","kind":"region"},{"name":"Bermuda","iso":"BM","kind":"region"},{"name":"British Virgin Islands","iso":"VG","kind":"region"},{"name":"Bonaire, Sint Eustatius and Saba","iso":"BQ","kind":"region"},{"name":"Cayman Islands","iso":"KY","kind":"region"},{"name":"Costa Rica","iso":"CR","kind":"region"},{"name":"Curaçao","iso":"CW","kind":"region"},{"name":"Dominica","iso":"DM","kind":"region"},{"name":"Dominican Republic","iso":"DO","kind":"region"},{"name":"El Salvador","iso":"SV","kind":"region"},{"name":"Greenland","iso":"GL","kind":"region"},{"name":"Grenada","iso":"GD","kind":"region"},{"name":"Guadeloupe","iso":"GP","kind":"region"},{"name":"Guatemala","iso":"GT","kind":"region"},{"name":"Haiti","iso":"HT","kind":"region"},{"name":"Honduras","iso":"HN","kind":"region"},{"name":"Jamaica","iso":"JM","kind":"region"},{"name":"Martinique","iso":"MQ","kind":"region"},{"name":"Montserrat","iso":"MS","kind":"region"},{"name":"Nicaragua","iso":"NI","kind":"region"},{"name":"Panama","iso":"PA","kind":"region"},{"name":"Puerto Rico","iso":"PR","kind":"region"},{"name":"Saint Kitts and Nevis","iso":"KN","kind":"region"},{"name":"Saint Lucia","iso":"LC","kind":"region"},{"name":"Saint Vincent and the Grenadines","iso":null,"kind":"region"},{"name":"Saint-Pierre and Miquelon","iso":"PM","kind":"region"},{"name":"Sint Maarten","iso":"SX","kind":"region"},{"name":"Trinidad and Tobago","iso":"TT","kind":"region"},{"name":"Turks and Caicos Islands","iso":"TC","kind":"region"},{"name":"United States Virgin Islands","iso":"VI","kind":"region"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","Cybersecurity","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-16T01:28:37Z"}],"liveness":{"score":4,"band":"cold","label":"Long shot","p_open":1,"p_active":0.132,"p_room":0.28,"age_days":250,"expected_fill_days":23,"reasons":["conf:7","win:tail","crowd:"],"computed_at":"2026-09-24T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/sprocket-security-penetration-tester","json_url":"https://alion.io/job/sprocket-security-penetration-tester.json","meta":{"generated_at":"2026-09-24T13:52:56Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}