Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Penetration Tester

Bishop Fox

Penetration Tester

Mexico, Remote

At Bishop Fox, security isn't just a job - it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation.

Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions - including 16 open-source tools and 50 security advisories published in the past five years - we're committed to making the digital world safer.

Given our exceptional growth, we are expanding and hiring a Pen Tester to join us on this exciting journey. We're looking for a talented, experienced professional hacker to help us secure some of the world's most complex software and sophisticated technologies. You'll be working alongside our US and internationally-based teams supporting clients across multiple industries.

Who Are You and What You'll Do

You're a cybersecurity consultant with a strong offensive security mindset and a passion for understanding how modern applications, cloud platforms, APIs, and emerging technologies operate at a deep technical level. You enjoy uncovering security weaknesses, thinking creatively about attack paths, and helping organizations solve complex security challenges through practical, risk-focused assessments.

At Bishop Fox, you'll work on a wide variety of security engagements including Cloud Security Assessments, Mobile Application Security Testing, Hybrid Application Assessments (HAA), and AI/LLM Security Assessments. You'll evaluate modern applications and distributed systems across cloud-native, mobile, backend, and AI-enabled environments.

Your responsibilities will include performing hands-on security testing, analyzing application behavior, reviewing source code, identifying realistic exploitation scenarios, and validating security controls across modern architectures. You'll work closely with clients and internal teams to deliver high-quality technical assessments and actionable remediation guidance.

As a consultant, you'll contribute throughout the full engagement lifecycle from scoping and test planning to execution, reporting, and client presentations. Success in this role requires strong technical depth, structured testing methodologies, effective communication skills, and the ability to adapt quickly to new technologies and environments.

Your Experience
  • 4+ years of experience in application security assessments, penetration testing, or offensive security engagements
  • Strong understanding of application security fundamentals, modern attack techniques, and common vulnerabilities affecting web applications, APIs, mobile applications, and cloud-native environments
  • Hands-on experience testing REST APIs, including authentication/authorization flaws, IDORs, injection vulnerabilities, session management issues, and business logic flaws
  • Strength with AWS services and cloud security concepts, including IAM, STS, S3, Lambda, API Gateway, CloudTrail, CloudWatch, and secure communication patterns such as SigV4
  • Solid understanding of networking and web fundamentals, including TCP/IP, DNS, API communication flows, cookies, headers, and related concepts
  • Experience reviewing source code for security issues in Java, C#, and Python applications
  • Knowledge of secure coding principles and common risks such as SSRF, insecure deserialization, injection vulnerabilities, sensitive data exposure, and insecure cloud integrations
  • Understanding of SDLC, CI/CD pipelines, and secure development practices
  • Experience using security assessment and code review tools such as Burp Suite, Semgrep, Git, AWS CLI, and API testing/debugging tools
  • Comfortable working across Linux, Windows, and macOS environments
  • Experience or strong interest in AI/LLM security, including prompt injection, RAG risks, insecure integrations, excessive permissions, and the OWASP Top 10 for LLM Applications
  • Strong written and verbal communication skills, with the ability to deliver clear, actionable findings and communicate technical risks to both technical and executive stakeholders
  • Experience following structured testing methodologies, documentation standards, and validation/retesting workflows
  • Strong collaboration and interpersonal skills when working with security, engineering, and client teams
  • Ability to manage multiple concurrent engagements while maintaining high-quality deliverables and attention to detail
  • Curious, adaptable, and professional mindset with a passion for continuous learning and emerging security trends
Why Bishop Fox

At Bishop Fox, we're driven by a simple mission: deliver exceptional quality to our clients, foster a vibrant and fulfilling environment for our team, and champion excellence within our industry. Our core values, which we live by every day, are:

  • Be Excellent to Each Other
  • Do the Right Thing
  • Do What You'll Say You'll Do
  • Get Better Together
  • Give a Sh*t

At Bishop Fox, we're committed to providing benefits that support your well-being and professional growth. Here's a glimpse of what we offer:

  • Generous Time Off and Company-Wide Holidays
  • Team Events and International Travel Opportunities
  • Work From Home Support
  • Training Budget
  • Saving Fund
  • Food Coupons
  • Health and Wellbeing programs

This position is not eligible for visa sponsorship. Applicants must be authorized to work in Mexico for the duration of employment without sponsorship.

Bishop Fox is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. All new hires must pass a background check as a condition of employment.

Interested? Apply today!

Vacancy posted 23 hours ago
Similar jobs that could be interesting for youBased on the Penetration Tester in United States vacancy
  • $86.8k - $198k

    Penetration TesterThe Opportunity:Conduct testing and analysis to identify vulnerabilities and potential threat vectors in systems and networks...  ...Certified Professional (OSCP), HTB Certified Penetration Tester Specialist (CPTS), eLearnSecurity Junior Penetration Tester (... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Herndon, VA
    1 day ago
  •  ...tested leadership, and trusted results to enable national security missions worldwide.Job DescriptionOverviewSOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting... 
    Suggested
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    1 day ago
  • DescriptionSAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan... 
    Suggested
    Work at office
    Local area
    Shift work
    3 days per week

    Science Applications International Corporation

    Beltsville, MD
    2 days ago
  • $90k - $130k

     ...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial... 
    Suggested
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    23 hours ago
  • $86k - $138k

    ResponsibilitiesPeraton is seeking an experienced Cyber Penetration Tester to become part of Peratons’ Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flexible as long as person can come on-site as & when needed. In this role, you will: Support the Red... 
    Suggested
    Contract work
    Flexible hours
    Shift work

    Peraton Corporation

    Arlington, VA
    2 days ago
  • $104k - $166k

    ResponsibilitiesPeraton is currently seeking to hire an experienced Penetration Tester for its Federal Strategic Cyber Group. Location: Chandler, AZ and Washington DC.Role and Responsibilities: We are seeking to hire an experienced and highly skilled Penetration Tester... 
    Contract work
    Currently hiring
    Shift work

    Peraton Corporation

    Washington DC
    2 days ago
  •  ...requirement to be onsite up to two (2) days a week at Quantico Marine Corps Base VA.Position Description: The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities... 
    Work at office
    Remote work
    2 days per week

    ASRC Federal Holding Company

    Quantico, VA
    4 days ago
  • $150k - $195k

    OverviewVTG is looking for multiple levels (Level 2, 3 & 4) of a Penetration Tester in Chantilly VA and Aurora CO. (Note: position is contingent upon program award and the postions are located in Chantilly VA & Auroro CO)A Penetration Tester (Pen Tester) is a security... 
    Work experience placement

    VTG

    Chantilly, Loudoun County, VA
    3 days ago
  •  ...be assigned based on business needs and individual expertise.Penetration TestingConduct penetration tests against enterprise applications...  ...: CISSP, CRISHack The Box: CPTS, Active Directory Penetration Tester, Web Exploitation Specialist, Web Exploitation Expert,... 
    Permanent employment
    Full time
    Part time
    H1b
    Work visa
    Shift work
    Day shift

    Truist

    Raleigh, NC
    3 days ago
  • ASRC Federal Technology Solutions is seeking an experienced Penetration Testerto lead advanced security assessments and contribute to the...  ....Manage and mentor a small team of junior penetration testers; provide technical guidance and training.Build and lead a Purple... 
    3 days per week

    ASRC Federal Holding Company

    Washington DC
    4 days ago
  • $122.57k - $204.25k

     ...opportunity to help evolve LPL’s offensive security capabilities.Job OverviewAs a member of the Cyber Security team, the Senior Penetration Tester, Offensive Security, is responsible for the scheduling, scoping, and execution of internal penetration testing, with a... 
    Full time
    Work from home

    LPL Financial

    Austin, TX
    2 days ago
  • $95.86k - $208.27k

     ...expand your capabilities, then consider a career in Advisory.KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice.Responsibilities:Conduct manual application penetration testing against API's (REST/SOAP... 
    H1b
    Local area

    KPMG

    Fort Worth, TX
    3 days ago
  • $124.54k - $180k

    GovCIO is currently hiring for a Senior Pentration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC.ResponsibilitiesThe Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability... 
    Currently hiring

    Govcio

    Washington DC
    1 day ago
  • $118k - $128k

     ...Information Technology, Test & Evaluation, Program Mission Support, Engineering & Analysis, and Training.ResponsibilitiesAs a SENIOR PENETRATION TESTER with AMERICAN SYSTEMS you will have the opportunity to do the following:Penetration Testing: Plan, execute, and report on... 
    For contractors

    AMERICAN SYSTEMS

    Middletown, RI
    2 days ago
  •  ...primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, and...  ...peer reviews of penetration test reports and mentoring junior testers.Continuous learner who keeps up with the latest offensive security... 

    JP Morgan Chase

    New York, NY
    1 day ago
  • $131.3k - $237.35k

    Senior ISSE/Penetration TesterLeidos has an exciting and challenging opportunity for a Senior ISSE/Penetration Tester in our Intel Sector’s Cyber & Analytics Business Area (CABA). Our talented team is at the forefront in Security Engineering, Computer Network Operations... 
    Full time
    Immediate start
    Flexible hours

    Leidos

    Annapolis Junction, MD
    4 days ago
  • $104.8k - $192.2k

     ...wherever you want it to go. Join EY and help to build a better working world.Government and Public Sector - Cybersecurity - Penetration Tester - Senior ConsultantFrom strategy to execution, the Government & Public Sector practice (“GPS”) of Ernst & Young provides a full... 
    For contractors
    Summer holiday
    Work at office
    Local area
    Flexible hours

    EY (Ernst & Young)

    McLean, VA
    3 days ago
  •  ...Senior Web Application Penetration Tester Remote SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise... 
    Full time
    Temporary work
    Remote work
    Flexible hours

    SIXGEN

    United States
    4 days ago
  •  ...Application Penetration Testers / Dynamic Application Security Testing (DAST) San Francisco CA or New York City, NY or Charlotte NC or Irving TX or Chandler AZ or Minneapolis MN (Hybrid 3-5 days onsite) 12+ Months Web cam Interview $55-$60/Hr on W2 In this contingent... 

    Syntricate Technologies

    Charlotte, NC
    1 day ago
  •  ...in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA   Our client seeks an experienced penetration testing professional to plan and execute comprehensive security assessments across applications, systems, and infrastructure in alignment... 
    Hourly pay
    Full time
    Contract work
    Temporary work
    Local area
    2 days per week
    3 days per week

    Eliassen Group

    Alexandria, VA
    4 days ago
  •  ...Penetration Tester Djamo is a Series B neobank serving over 1 million customers across Francophone Africa. We're the first fintech to receive a BCEAO microfinance license and the leading card issuer in Côte d'Ivoire. Our engineering team is 27 strong, organized into... 
    Contract work
    Work at office
    Immediate start
    Remote work

    Djamo

    United States
    23 hours ago
  •  ...our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted...  ...Responsibilities You’re a penetration tester who knows their way around source code. You’ve plundered apps... 
    Full time
    Temporary work
    Local area
    Remote work

    Bishop Fox

    Remote
    6 days ago
  •  ...Software Secured Penetration Tester Software Secured is a leading Penetration Testing as a Service company, with a head office in beautiful Ottawa, Canada. We help software development teams get ahead of hackers using a suite of services and products. Our team of... 
    Permanent employment
    Work at office
    Remote work
    Home office
    Work visa

    Software Secured

    United States
    1 day ago
  •  ...Hiring Web and Mobile Application Penetration Testers Job Title – Application Penetration Tester (Senior – Principal) Shorebreak Security is looking for passionate, self-disciplined, motivated application penetration test professionals to join our team. Live where... 
    Permanent employment
    Full time
    Contract work
    Remote work
    Flexible hours

    Shorebreak Security, Inc

    Cocoa Beach, FL
    more than 2 months ago
  •  ...Penetration Tester Locations: Los Angeles (CA), Dallas (TX), Washington DC. Responsibilities: Assist in project scoping and SOW creation Perform offensive engagements including red teaming and penetration testing Perform penetration tests against external... 
    Work experience placement

    WATI

    Washington DC
    1 day ago
  •  ...Penetration Tester As a member of our Attack & Pentest team, you will serve as a frontline analyst responsible for validating, prioritizing, and driving the closure of security vulnerabilities across the enterprise. You will assess findings for exploitability and business... 
    Remote work

    Alpine Solutions Group

    United States
    23 hours ago
  • $125k - $155k

     ...Penetration Tester Fortreum is a trusted leader in cloud and cybersecurity services, ranked among the Top 5 FedRAMP Third Party Assessment Organizations (3PAO). With the addition of Kovr.AI, we have expanded our capabilities to include advanced cyber risk quantification... 
    Temporary work
    Remote work
    Home office
    Flexible hours

    Fortreum

    United States
    23 hours ago
  •  ...Offensive Security Consultant (Penetration Tester) At WorkNest Secure, we help organizations strengthen their cyber security posture through industry-leading security services and solutions. As we continue to grow, we're looking for talented CHECK Team Members to join... 
    Remote work
    Flexible hours

    Work Nest

    United States
    2 days ago
  •  ...the cybersecurity and information assurance sector, is seeking a dedicated and skilled Vulnerability Assessment Analyst and Penetration Tester 3 to join their dynamic team. As a Vulnerability Assessment Analyst and Penetration Tester 3, you will be an integral part of... 
    Weekly pay
    Temporary work
    Remote work
    Flexible hours

    ManpowerGroup Global, Inc.

    Overland Park, KS
    1 day ago
  •  ...Penetration Tester Since 1998, Lostar is the leading Information Security firm, with more than 1000 projects in Turkey and abroad. Its main services are; Information Security Checkups such as Internet-Intranet Penetration Tests, Gap Analysis of world-wide best practices... 
    Remote work
    Flexible hours

    Lostar

    United States
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Penetration Tester. Be the first to apply!