.Jul 27, 2024 - Bishop Fox is hiring a remote Senior Penetration Tester. Location: Mexico.Bishop Fox is the leading authority in offensive security, providing solutions ranging from continuous penetration testing, red teaming, and attack surface management to product, cloud, and application security assessments. We've worked with more than a quarter of the Fortune 100, half of the Fortune 10, eight of the top 10 global technology companies, and all of the top global media companies. Our Cosmos platform, service innovation, and culture of excellence continue to gather accolades from industry award programs including Fast Company, Inc., SC Media, and others. For more than 16 years, we've been contributing and giving back to the security community. We've published more than 16 open source tools and 50 security advisories in the last five years alone. Learn more at bishopfox.Com or follow us on social media.We're looking for talented, experienced professional hackers to help us secure some of the world's most complex software and sophisticated technologies. You'll be working alongside our Mexico, US, and other internationally-based teams supporting clients across multiple industries.ResponsibilitiesYou're a penetration tester who knows their way around source code. You've plundered apps and pillaged networks (legally, of course). You have a passion for hacking and information security. You may also have written a few blog posts about your favorite hacks or have presented at a handful of conferences – with an eye to doing more.With Bishop Fox, your responsibilities would include testing web applications, hacking networks, and reversing software. As a consultant, you'll work on a variety of projects which include short-term engagements and extended program work with well-established clients. You'll solve challenging technical problems and build creative solutions. As a trusted advisor, you'll provide your expert opinion to help our clients navigate difficult business decisions.Requirements7+ years experience in planning, conducting, and managing web application penetration tests5+ years of application security experienceDeep understanding of security fundamentals (OWASP), common vulnerabilities, and application security best practicesSkilled in vulnerability assessment and the development of exploits for diverse targetsBackground in system and network security, authentication and security protocols, and applied cryptography is helpfulExperience with programming and scripting languages such as Python, Ruby, PowerShell, Java, JavaScript, etc.Experience with AWS cloud environments preferred with an understanding of its major technologies, such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambdas, and how to keep them secureProficiency with operating systems- Linux, Windows, MacOSExperience with network and system exploitation including modern tactics, techniques, and procedures (e.G