Cybersecurity Penetration Tester

ITR GroupBrooklyn Park, MN

About The Position

Long term contract consulting opportunity for an experience Penetration Test. Client Requirements: Must be W2 hourly (no C2C) Work authorization requirements: US Citizen or GC holder Seeking an experienced Penetration Tester to identify, assess, and validate security vulnerabilities across web applications, APIs, and enterprise systems. This role will lead end-to-end penetration testing engagements, partner closely with engineering teams to remediate findings, and help strengthen the organization's overall security posture through proactive testing and risk assessments.

Requirements

  • 7+ years of cybersecurity experience with increasing responsibility in penetration testing.
  • 5+ years of hands-on penetration testing experience focused on web applications and APIs within enterprise environments.
  • Strong knowledge of web application security vulnerabilities, including OWASP Top 10, authentication and authorization flaws, and injection attacks.
  • Advanced proficiency with Burp Suite, Nmap, and common exploitation frameworks.
  • Experience developing automation or testing scripts using Python or Go.
  • Strong analytical, communication, and documentation skills with the ability to deliver clear, actionable security findings.
  • Proven experience collaborating with engineering teams to validate and remediate vulnerabilities.
  • US Citizen or GC holder

Nice To Haves

  • Experience testing mobile applications, embedded systems, hardware, or third-party/vendor platforms.
  • Familiarity with PCI penetration testing requirements and regulatory compliance.
  • Experience supporting or managing bug bounty programs.
  • Knowledge of threat modeling and identifying security risks during application design and development.

Responsibilities

  • Conduct end-to-end penetration testing engagements, including scoping, exploitation, validation, and reporting.
  • Perform security assessments of web applications and APIs, identifying vulnerabilities and recommending effective remediation strategies.
  • Utilize industry-standard security testing tools such as Burp Suite, Nmap, and exploitation frameworks to identify security risks.
  • Develop Python or Go scripts to automate testing activities and improve penetration testing workflows.
  • Document vulnerabilities clearly and provide actionable remediation guidance for engineering teams.
  • Collaborate with development and engineering teams to validate fixes and verify vulnerability remediation.
  • Support secure development initiatives by identifying risks early and contributing to threat modeling activities.
  • Assist with PCI-related penetration testing and compliance efforts as needed.
  • Contribute to bug bounty programs by validating, triaging, and escalating reported vulnerabilities.
  • Continuously evaluate and improve penetration testing methodologies, tools, and processes.
  • Mentor junior team members and provide technical guidance on penetration testing best practices.

Benefits

  • medical
  • dental
  • 401(k) for eligible employees
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service