We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, inclusive culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM.
The Penetration Tester conducts authorized security assessments of applications, APIs, and network infrastructure to identify vulnerabilities and security weaknesses. Working closely with development, infrastructure, and security teams, the Penetration Tester leverages technical expertise, creativity, and an attacker mindset to identify and exploit weaknesses in internally developed and third-party systems.
The ideal candidate is responsible for performing security assessments, documenting findings, validating remediation efforts, and providing actionable recommendations based on industry best practices. The ideal candidate has experience with application and network penetration testing, a strong understanding of secure development principles, and familiarity with modern security testing methodologies including OWASP Top 10, SANS Top 25, and API security testing.
Responsibilities
Perform web application, API, and network security assessments.
Identify, exploit, and validate security vulnerabilities in applications and infrastructure.
Create test cases, document findings, and track remediation activities in Azure DevOps.
Provide risk-based security recommendations and guidance to stakeholders.
Validate remediation efforts and conduct retesting of previously identified vulnerabilities.
Research emerging threats, attack techniques, and industry security trends.
Assist in developing and automating penetration testing methodologies and security processes.
Participate in the creation of technical and executive-level assessment reports.
Utilize AI-assisted tools and techniques where appropriate to improve testing efficiency and coverage.
Perform other duties as assigned.
Qualifications
EDUCATION
Bachelor’s degree in computer science, Cybersecurity, Information Technology, or equivalent experience.
CERTIFICATIONS (preferred)
GPEN (GIAC Penetration Tester)
CEH (Certified Ethical Hacker)
Security+
CISSP
TECHNICAL SKILLS
Required
Experience performing web application and network penetration testing.
Proficiency with Burp Suite Professional.
Understanding of OWASP Top 10, SANS Top 25, and common attack methodologies.
Ability to read, understand, and audit source code during source code-assisted penetration testing.
Strong understanding of authentication, authorization, session management, and common application security vulnerabilities.
Experience creating clear and actionable technical documentation and reports.
Experience With:
Programming Languages: C#, Java, JavaScript, Python, or similar.
Scripting/Automation: Python, PowerShell, Bash, or equivalent.
API Security Testing (REST, GraphQL, SOAP).
Azure DevOps or similar ticketing and defect tracking platforms.
Linux and Windows operating systems.
Cloud Platforms (Azure, AWS, or GCP).
Preferred
Experience testing AI-enabled applications and Large Language Model (LLM) integrations.
Familiarity with OWASP Top 10 for LLM Applications.
Experience leveraging AI-assisted security testing tools and workflows.
EXPERIENCE
Required
3-5+ years of experience in penetration testing, application security, or cybersecurity engineering.
Experience conducting application and network penetration tests in enterprise environments.
Experience writing professional technical and executive-level security reports.
LEADERSHIP & COMMUNICATION
Required
Strong verbal and written communication skills.
Ability to communicate technical findings to technical and non-technical audiences.
Strong collaboration skills with Security Leads, Managers, Developers, and Infrastructure teams.
Ability to manage multiple projects and meet deadlines in a fast-paced environment.
Strong analytical, troubleshooting, and problem-solving skills.
At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at https://rsmus.com/careers/working-at-rsm/benefits https://rsmus.com/careers/el-salvador.html.
RSM does not tolerate discrimination and/or harassment based on race; colour; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender (including gender identity and/or gender expression); sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the Salvadoran Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable provincial employment legislation.
Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership. RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please send us an email at [email protected].
Skills Required
- Bachelor's degree or equivalent experience
- 3-5+ years of experience in cybersecurity engineering or penetration testing
- Proficiency with Burp Suite
- Experience with DAST tools and dynamic application security testing
- Ability to read and audit source code during source-assisted penetration testing
- Experience with C#, Java, Python, or PowerShell
- Experience creating test cases and logging defects in Azure DevOps
- Strong communication and collaboration skills; ability to work with security leads/managers
- CISSP, Security+, CEH
RSM US LLP Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about RSM US LLP and has not been reviewed or approved by RSM US LLP.
-
Parental & Family Support — Parental leave, caregiver leave, and family‑building assistance are standout strengths, including 12 weeks fully paid parental leave, six weeks paid family caregiver leave, up to $50,000 in fertility coverage, and up to $20,000 per child for adoption or surrogacy, plus backup care resources. These benefits create a family‑forward package that stands out within the firm’s total rewards.
-
Leave & Time Off Breadth — Time‑off options are broad, with self‑managed PTO for associates and above, at least 14 paid holidays, and firm‑wide wellbeing days alongside hybrid work flexibility. This breadth is consistently presented as a strong component of the overall offering.
-
Healthcare Strength — Medical coverage includes multiple plan designs (two HDHPs and a PPO), telehealth access, and a mental‑health platform offering up to eight free 1:1 sessions per year. Health benefits are characterized as solid to strong for the industry.
RSM US LLP Insights
What We Do
RSM is the leading provider of audit, tax and consulting services to the middle market. With over 11,000 employees across the U.S. and Canada and a global presence in 120 countries, our purpose is to deliver the power of being understood to our clients, colleagues and communities. As first-choice advisors, we are focused on developing leading professionals and innovative services to meet our clients’ evolving needs in today’s ever-changing business environment. Through a supportive, caring culture, our people are empowered to be their authentic selves and share their unique perspectives. Our culture of diversity and inclusion enhances the insights we provide while transforming innovation, collaboration and business results through fostering an inclusive environment, working hard to engage a talented workforce and reflect our diverse community, and developing relationships that serve others in business and the broader community. Together, our people’s individual talents and diverse perspectives strengthen our teams and enhances the unique insights that we provide to our clients. Through a supportive, caring culture, our people are empowered to be their authentic selves and share their unique perspectives. Our culture of diversity and inclusion enhances the insights we provide while transforming innovation, collaboration and business results through fostering an inclusive environment, working hard to engage a talented workforce and reflect our diverse community, and developing relationships that serve others in business and the broader community. Together, our people’s individual talents and diverse perspectives strengthen our teams and enhances the unique insights that we provide to our clients. For more information, visit rsmus.com.






