Penetration Tester

Posted 58 Minutes Ago
Be an Early Applicant
19 Locations
Remote or Hybrid
130K-165K Annually
Senior level
Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Our mission is to simplify IT operations, making IT teams more efficient and users more productive.
The Role
Perform penetration testing across applications, APIs, cloud environments, infrastructure, and client-side components. Identify, validate, score, and document vulnerabilities; support remediation and secure design with Engineering; triage bug bounty submissions; develop testing tools and scripts; and communicate findings to researchers, technical teams, and executives. The role also applies threat modeling, security frameworks, and emerging threat intelligence to improve organizational security.
Summary Generated by Built In

About the Role 

The Penetration Tester role is a key part of NinjaOne's core security team, with visibility across the entire organization, from individual developers to executive leadership. You will directly strengthen the security of the NinjaOne platform by identifying and helping resolve technical, security, and architectural vulnerabilities across our applications and environments. The ideal candidate takes a multi-layered approach to uncovering weaknesses in software, web applications, and client-side components to drive meaningful security improvements. This role is also a key contributor to NinjaOne's public bug bounty program, validating externally reported vulnerabilities and working directly with security researchers around the world.

Location: We are flexible on remote working from home, if you are located in the USA and reside in one of the following states: CA, CO, CT, FL, GA, *IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA. We have physical offices in Austin, TX and Tampa, FL, if you prefer a hybrid option.

*Onsite interviews may be required for this role.

What You'll Be Doing 

  • Perform controlled penetration testing of NinjaOne applications, cloud environments, and infrastructure, demonstrating exploitability and documenting risks and remediation steps
  • Perform security testing of new and modified API endpoints and features as part of each release cycle, prioritizing coverage against release timelines
  • Collaborate with Engineering to validate vulnerabilities, communicate impact, and support secure design and remediation efforts
  • Develop custom tools or scripts to support penetration testing, automation, and exploit development
  • Perform first-pass triage and validation of bug bounty submissions: reproduce reported issues, assess severity and impact (CVSS), identify duplicates, and route confirmed findings to the appropriate teams
  • Communicate directly with external security researchers in clear, professional written English throughout the report lifecycle
  • Stay current on emerging threats, TTPs, and cybersecurity trends, applying them to evaluate NinjaOne's exposure and guide security initiatives
  • Create clear, comprehensive reports and presentations for both technical and executive stakeholders
  • Promote security awareness across the organization, contributing to policies, best practices, and ongoing security education
  • Other duties as needed

About You 

  • Bachelor's degree in Information Technology, Computer Science, or a related field
  • 8+ years of hands-on penetration testing experience, within a broader 5+ years in cybersecurity-related roles
  • Strong understanding of security protocols, cryptography, authentication/authorization, and modern attack techniques
  • Security certifications such as OSCP (highly desired) and/or Security+, CISSP, or CISM are a plus
  • Proficiency with penetration testing tools such as Burp Suite, Caido, and related frameworks
  • Experience validating and scoring vulnerabilities (CVSS) and communicating findings to both technical and non-technical audiences; bug bounty triage or program experience is a strong plus
  • Ability to develop custom testing tools or scripts (Java, Kotlin, C++, Python, or Go)
  • Knowledge of security frameworks and methodologies (OWASP, NIST, BSIMM), threat modeling (STRIDE, DREAD), and system hardening standards (CIS, CSA)
  • Solid understanding of Linux and Windows operating systems, enterprise architecture, and TCP/IP and UDP networking fundamentals
  • Experience testing or exploiting cloud-native applications; understanding cloud security architecture is a plus
  • Strong analytical and problem-solving skills with excellent written and verbal communication; this role communicates directly with external security researchers, engineers, and leadership

About Us 

NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years.

What You'll Love 

  • A collaborative, kind, and curious community
  • Full-time work that is hybrid remote, honoring your flexibility needs
  • A comprehensive benefits package, including medical, dental, and vision insurance
  • A 401(k) plan to help you prepare for your financial future
  • Unlimited PTO that prioritizes your work-life balance
  • Opportunity for growth and advancement

Additional Information 

This position is NOT eligible for Visa sponsorship.

*Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.

Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage, and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington, the base salary hiring range for this position is $130,000 to $165,000 per year.

For roles based in New York, the base salary hiring range for this position is $130,000 to $165,000 per year.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.

 

Skills Required

  • Bachelor’s degree in Information Technology, Computer Science, or a related field
  • 8+ years of hands-on penetration testing experience
  • 5+ years in cybersecurity-related roles
  • Strong understanding of security protocols, cryptography, authentication, authorization, and modern attack techniques
  • Proficiency with penetration testing tools such as Burp Suite, Caido, and related frameworks
  • Experience validating and scoring vulnerabilities using CVSS
  • Ability to develop custom testing tools or scripts using Java, Kotlin, C++, Python, or Go
  • Knowledge of OWASP, NIST, BSIMM, STRIDE, DREAD, CIS, and CSA frameworks or methodologies
  • Solid understanding of Linux and Windows operating systems, enterprise architecture, and TCP/IP and UDP networking
  • Experience testing or exploiting cloud-native applications
  • Strong analytical, problem-solving, written communication, and verbal communication skills
  • OSCP, Security+, CISSP, or CISM certification
  • Bug bounty triage or program experience
  • Understanding of cloud security architecture

NinjaOne Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about NinjaOne and has not been reviewed or approved by NinjaOne.

  • Healthcare Strength — Health coverage spans medical, dental, and vision with a notable employer premium contribution, alongside mental-health and wellness programs. This combination indicates robust support for routine and preventive care.
  • Leave & Time Off Breadth — Policies highlight unlimited or flexible PTO alongside paid holidays and sick time, as well as generous parental leave. Flexible scheduling and hybrid/remote options reinforce time-off usability.
  • Fair & Transparent Compensation — Pay is characterized as decent to good overall and competitive for many engineering and senior IC roles. Publicly posted ranges and salary snapshots align to market-typical totals in several functions.

NinjaOne Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Austin, TX
2,000 Employees
Year Founded: 2013

What We Do

NinjaOne, the automated endpoint management platform, delivers visibility, security, and control over all endpoints for more than 30,000 customers in 130+ countries. The cloud-native NinjaOne platform simplifies endpoint management, patching, and visibility for environments at any scale. It is proven to increase productivity, reduce security risk, and lower costs. 

Why Work With Us

NinjaOne is proud to be an independent, founder-led company. NinjaOne is filled with passionate, driven people of all backgrounds. We’re proud to celebrate our differences and build a company based on integrity, inclusion and acceptance. We invest in our staff and implement a policy of transparency with a flat organizational structure.

Gallery

Gallery

Similar Jobs

Velero Consulting Logo Velero Consulting

Penetration Tester

Information Technology • Professional Services • Consulting • Cybersecurity
In-Office or Remote
2 Locations
300 Employees
120-160 Hourly

Amyx, Inc. Logo Amyx, Inc.

Sr. Penetration Tester

Information Technology • Other
Remote
United States
501 Employees
Remote
USA
81 Employees

SIXGEN Logo SIXGEN

Senior Web Application Penetration Tester

Hardware • Security • Software • Cybersecurity
Remote
USA
59 Employees
100K-135K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account