Sr Penetration Testing Engineer
Bright Defense · Offensive Security · Now Hiring
Senior Penetration Tester
Web, API & Mobile — Senior Level
We’re looking for a senior tester who owns engagements end to end — scoping, testing, reporting, and retesting — and who has already put AI to work in the testing workflow. You’ll set the quality bar for our testing team and mentor the people coming up behind you.
About Bright Defense
Bright Defense is dedicated to safeguarding our clients’ digital assets by identifying, assessing, and mitigating security vulnerabilities. We partner with a diverse range of customers to keep their web applications, APIs, and mobile apps protected against evolving threats. Our offensive security work feeds directly into the compliance and remediation programs we run for clients across defense, healthcare, fintech, and SaaS.
Key responsibilities
Customer-focused testing
- Plan, execute, and manage penetration tests for Bright Defense customers, focused on web applications and APIs
- Conduct manual and automated testing to identify security flaws, misconfigurations, and exploitation paths
- Scope engagements and set rules of engagement, timelines, and success criteria with customers
- Perform retesting and validate that fixes actually hold
Quality assurance & mentorship
- Review and validate reports, findings, and recommendations produced by other testers
- Provide constructive feedback and mentoring to junior and mid-level testers
- Maintain and improve internal testing methodology and deliverable standards
Remediation & risk
- Deliver clear, actionable remediation strategies customers can execute
- Collaborate with client development teams on secure coding and improved controls
- Perform threat modeling to proactively identify and assess risk
- Recommend countermeasures that measurably reduce threat exposure
Reporting & collaboration
- Write detailed technical reports and executive summaries for different audiences
- Document methodologies and findings to support compliance and audit requirements
- Work alongside client project managers, DevOps, and IT security teams
- Support incident response and post-incident reviews when requested
AI-assisted testing
How we expect you to work
- Use AI to move faster. LLM-assisted recon, payload generation, source code review, and report drafting — with every finding independently validated before it reaches a customer
- Test AI itself. Prompt injection, insecure output handling, and data leakage in LLM-backed customer features
- Build the workflow. Help develop our internal AI-assisted testing prompts, tooling, and guardrails
- Know the limits. Be ready to talk through where AI sped you up, where it produced garbage, and how you verify its output
Qualifications
Required
- OSCP certification
- 5+ years in offensive security with hands-on testing of web applications and APIs (REST, GraphQL)
- Demonstrated use of AI tooling as part of the testing workflow
- Strong command of the OWASP Top 10, OWASP API Security Top 10, CWE, and modern authn/authz flaws
- Burp Suite Pro, Metasploit, Nmap, ffuf, and comparable tooling
- Scripting in Python, Bash, or PowerShell for custom tooling and exploits
- Excellent written and verbal communication with both engineers and executives
- Bachelor’s degree in a related field or equivalent experience
Preferred
- Mobile application testing on iOS and Android — static and dynamic analysis, traffic interception, pinning bypass, insecure local storage, mobile API abuse
- OWASP MASVS/MASTG, Frida, Objection, MobSF
- Cloud security in AWS, Azure, or GCP, including privilege escalation paths
- Red team engagements or adversary simulation
- Thick client, network, or internal infrastructure testing
- Security controls in CI/CD pipelines (DevSecOps)
- Bug bounty or responsible disclosure participation
- Exposure to SOC 2, ISO 27001, PCI DSS, HIPAA, or CMMC
Relevant certifications
Why you’ll love this role
Real variety of targets — web, API, cloud, and mobile — instead of the same engagement on repeat
Freedom to shape how a growing security firm uses AI in offensive testing, not just permission to try it
Senior scope from day one: own engagements, set the quality bar, and mentor the testers behind you
Compensation & perks
- Competitive base salary — range shared during screening
- Remote-first with flexible working hours
- Certification reimbursement — OSWE, OSEP, GWAPT, GMOB, and more
- Dedicated lab time and access to AI tooling for security work
- Direct access to Bright Defense co-founders and leadership
- Client exposure across defense, healthcare, fintech, and SaaS
How to apply
Send your resume, a short note on your testing background, and any relevant work samples — sanitized reports, tooling, CVEs, or bug bounty writeups — to careers@brightdefense.com.