What You'll Do
- Working independently and collaboratively with a team to both lead and support
- Perform penetration testing on applications with complex technology stacks from both a: Blackbox perspective & Whitebox perspective
- Dynamically flex your skills when assessing emerging or custom technologies
- Lead complex engagements to provide a technical consistency approach across multiple tests
- Contextualize vulnerabilities and assess realistic impact to a client accounting for mitigating and aggravating factors
- Manage priorities and tasks to achieve utilization targets
- Operate with professionalism both internally and with clients
- Ensure quality reports and services are delivered efficiently and on time
- Support sales and business growth by scoping out potential opportunities
- Maintains strong depth of knowledge in the practice area
- Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables
- Travel up to 10%
What You'll Bring
- Application penetration testing and assessment tradecraft and methodologies (including browser-based, API)
- Strong working knowledge of at least two programming or scripting languages
- Strong understanding of security principles and industry best practices.
- Minimum of 5 years’ experience in a consulting/professional services role
- Minimum of 5 years’ experience in Application Security and/or Software Development
- Expert proficiency in Web Application Penetration Testing
- Excellent overall technical skills, with strong expertise in at least one of the following:
- Mobile Application Penetration Testing
- Thick Application Penetration Testing
- Hardware Penetration Testing
- Secure Code Review
- Container Penetration Testing
- Cloud Penetration Testing
- Network Active Directory Penetration Testing
- AI Penetration Testing
- Excellent consulting skills including:
- Time management, performing adjacent tasks while ensuring on-time delivery, escalating issues as needed
- Verbal communication, leading client calls for project kickoffs and debrief
- Written communication & Report writing, for both executive audiences and technical staff
- High school diploma required
Bonus Points
- UK CREST Certification and eligibility to be approved for and maintain UK SC level Clearance
- Strongly preferred CREST Certifications
- CREST Practitioner Security Analyst (CPSA)
- CREST Practitioner Threat Intelligence Analyst (CPTIA)
- AWAE, OSCP, OSCE, OSEE offensive security certifications
- Significant development and engineering backgrounds
- Cloud Service penetration testing tradecraft and methodologies across multiple service providers (e.g. AWS, GCP, etc.).
- Mobile platform and application penetration testing tradecraft and methodologies across both iOS and Android.
- Red/Purple Team tradecraft and methodologies
- Social engineering in all its forms
- AWS Certified Solutions Architect – Professional, AWS Certified Security, AWS Certified Advanced Networking, AWS Certified SysOps Administrator
- Network, Database, System administration experience and certifications
Coalfire Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Coalfire and has not been reviewed or approved by Coalfire.
-
Leave & Time Off Breadth — Flexible paid time off and paid parental leave are prominently offered, with remote/WFH support enabling time away when workload allows.
-
Healthcare Strength — Comprehensive medical, dental, vision, wellness resources, and an EAP are part of the core package. Carrier coverage and plan options are regularly highlighted across employer materials.
-
Retirement Support — A company‑matched 401(k) is included alongside other financial and development perks. This retirement benefit is consistently featured across benefits overviews.
Coalfire Insights
Similar Jobs
What We Do
Coalfire is the cybersecurity advisor that helps private and public sector organizations avert threats, close gaps, and effectively manage risk. By providing independent and tailored advice, assessments, technical testing, and cyber engineering services, we help clients develop scalable programs that improve their security posture, achieve their business objectives, and fuel their continued success. Coalfire has been a cybersecurity thought leader for more than 20 years and has offices throughout the United States and Europe.







