Penetration Tester

Workstreet · Philippines

RemoteWorkplace
1w agoPosted · Aug 9
HimalayasSource
Apply now Opens the original posting at Workstreet. PivotHop does not host applications.

Skills in this posting

Extracted from the posting text by the instrument — the demand side, read literally.

The posting

About Workstreet

At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

Get to know the Security Services Team

We are the team that turns complex security requirements and compliance frameworks into infrastructure and services that actually work.

Moving fast and taking true end-to-end ownership, our team spans three core functions: Cloud Security Engineering , where we design hardened AWS, Azure, and GCP environments, write Terraform baselines, and fix failing controls to meet frameworks like SOC 2, ISO 27001, CMMC, and FedRAMP; Penetration Testing , where we run disciplined offensive assessments across networks, apps, cloud, and AI/LLM systems to catch vulnerabilities before adversaries do; and Vulnerability Management , where we continuously prioritize, patch, and validate risk reduction across the client footprint.

We do not hide behind process or just point out gaps. We step in, build solutions, and deliver real security posture improvements with minimal disruption.

What makes this team special isn't just our technical depth; it is how we back each other up. Our strongest engineers and assessors are the ones building reusable modules, writing custom tools, jumping into channels to unblock teammates, and mentoring without being asked.

From early-stage startups to regulated enterprises, you will work directly with clients, take on real ownership early, and be surrounded by people who want to see you get good.

If you enjoy solving tough security problems and want to be part of a team that is scrappy enough to move fast but seasoned enough to get it right, you will be in good company here.

The Opportunity

We are seeking a Penetration Tester to join our growing cybersecurity team. In this role, you will assess the security of applications, networks, and systems through structured penetration testing and vulnerability assessments. You will help identify weaknesses, document findings, and provide actionable recommendations to strengthen clients’ security defenses.

What you'll do

Execute comprehensive penetration tests across web, mobile, network, and system environments to uncover, exploit, and validate critical infrastructure and application vulnerabilities.

Produce high-fidelity technical reports mapping out exploit impact and proof-of-concept chains, translating complex risk metrics into actionable remediation roadmaps for clients.

Partner directly with client engineering teams to guide post-assessment remediation, troubleshoot implementation blocks, and systematically verify the integrity of deployed fixes.

Engineer custom testing scripts, automation tools, and offensive methodologies to continuously expand vulnerability discovery coverage and testing precision.

Deploy tactical social engineering simulations , including targeted phishing and pretexting campaigns, to rigorously audit human security awareness and organizational defenses.

Support active incident response loops by providing offensive technical expertise, investigating compromise vectors, and accelerating threat containment pipelines.

Own the supporting client experience by maintaining transparent communications, gathering environmental prerequisites, and breaking down testing footprints into clear, business-friendly milestones.

Track the evolving threat landscape to continuously integrate cutting-edge exploit techniques, active vector changes, and defensive counter-measures into live assessment playbooks.

Who you are

Active offensive security operator - Command a proven history of executing structured penetration tests, vector mapping, and threat validation across complex application, network, and system environments.

Master of offensive frameworks - Deployed industry-standard testing platforms, exploitation architectures, and reporting frameworks to uncover hidden systemic security vulnerabilities.

Surgical exploit and validation engineer - Exploited, classified, and cataloged multi-tier security vulnerabilities, providing clear remediation roadmaps to client engineering teams to securely validate system fixes.

Precision technical author - Formulated high-fidelity assessment documentation, exploit chain proofs, and detailed impact reports that translate complex threat data into highly structured, actionable guidance.

High-impact security diplomat - Articulated tactical risk scenarios, testing footprints, and remediation expectations with professional clarity to both deep technical infrastructure teams and executive client stakeholders.

Social engineering and automation developer - Engineered custom testing scripts, targeted phishing simulations, and pretexting campaigns to audit human security awareness and expand overall assessment coverage.

Autonomous remote operator - Command an advanced local testing station fully optimized for heavy virtual machine deployment, maintaining peak operational velocity during standard US Eastern Time working hours.

Validated offensive security specialist - Hold or actively pursue high-value technical designations such as OSCP, CEH, or equivalent credentials that demonstrate a rigorous commitment to offensive security practices.

What help you succeed

Advanced cloud security auditing - Direct execution of cloud infrastructure penetration tests, container security evaluations, and environment configuration audits within AWS, GCP, or Azure.

Integration of GRC compliance frameworks - Practical alignment of technical vulnerability data to satisfy the automated audit and evidence requirements of SOC 2, GDPR, or HIPAA.

Commercial tenure in high-velocity startups - Years spent scaling offensive security workflows, handling rapid client delivery timelines, and adapting to shifting priorities within fast-growth tech environments.

Incident containment and threat training - Direct support of active incident response containment loops, or the design and execution of technical employee threat awareness initiatives.

What we offer

Career Development : Clear path with mentorship and training opportunities.

Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.

Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.

Growth Opportunity : Early-stage company with significant room for career advancement.

Remote-First Culture : Flexibility to work from anywhere while collaborating with a global team.

What you'll need to thrive

Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.

Excerpt from the original listing. The full, current text lives at the source. Read and apply there →

The PivotHop read

Where these skills also reach

Adjacent occupations measured from the same postings — readiness is what a penetration tester’s profile already covers.

More penetration tester roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves