Job Description
Senior Penetration Tester
PlutoSec is a leading cybersecurity and penetration testing company delivering manual security assessments for organizations across the United States and Canada. We are looking for an experienced Penetration Tester to join our growing offensive security team.
Responsibilities
- Perform Web Application Penetration Testing
- Conduct API Security Assessments
- Mobile Application Security Testing (iOS & Android)
- Internal & External Network Penetration Testing
- Active Directory Security Assessments
- Cloud Security Assessments (Azure, AWS & GCP)
- Validate vulnerabilities manually using industry-leading tools
- Prepare professional technical and executive reports
- Work directly with clients during remediation and retesting
Requirements
- 3+ years of penetration testing experience
- Strong knowledge of OWASP Top 10 & API Security Top 10
- Experience with Burp Suite Professional, Nmap, Metasploit, Wireshark, Nessus, Invicti or Acunetix
- Experience with Active Directory, Windows & Linux
- Knowledge of Azure, AWS or Google Cloud
- Strong reporting and communication skills
- Relevant certifications such as OSCP, PNPT, CEH, CRTO, GPEN or equivalent are an asset
Preferred Skills
- Red Team Operations
- Web Application Security
- API Security Testing
- Cloud Security
- Malware Analysis
- Digital Forensics
- Source Code Review
- DevSecOps
Why Join PlutoSec?
- Work on enterprise penetration testing engagements
- Collaborative cybersecurity team
- Career growth and continuous learning
- Flexible work environment
- Exposure to modern attack techniques and security technologies
Skills Required
- 3+ years of penetration testing experience
- Strong knowledge of OWASP Top 10 & API Security Top 10
- Experience with Burp Suite Professional, Nmap, Metasploit, Wireshark, Nessus, Invicti or Acunetix
- Experience with Active Directory, Windows & Linux
- Knowledge of Azure, AWS or Google Cloud
- Strong reporting and communication skills
- Relevant certifications such as OSCP, PNPT, CEH, CRTO, GPEN or equivalent
What We Do
PlutoSec is a leading cybersecurity and penetration testing company providing comprehensive security services to businesses across Canada, the United States, and globally. We help organizations identify, validate, and remediate security vulnerabilities before attackers can exploit them. Our services include web application penetration testing, API security testing, mobile application penetration testing (iOS & Android), external and internal network penetration testing, cloud security assessments for Microsoft Azure, AWS, and Google Cloud, Active Directory security assessments, Microsoft 365 security reviews, vulnerability assessments, red team engagements, malware analysis, digital forensics, incident response, ransomware recovery, managed security services (MSSP), and continuous security monitoring. Beyond offensive security, PlutoSec assists organizations in achieving compliance with SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, PHIPA, NIST, and CIS Controls through security assessments, compliance consulting, gap assessments, policy development, and remediation guidance. Unlike organizations that rely primarily on automated vulnerability scanners, PlutoSec combines advanced security tools with extensive manual penetration testing performed by certified cybersecurity experts. This human-led approach uncovers complex business logic flaws, authentication weaknesses, privilege escalation paths, API vulnerabilities, cloud misconfigurations, and other critical security risks that automated scanners often fail to detect. From startups and healthcare providers to financial institutions, SaaS companies, government organizations, and enterprises, PlutoSec delivers practical, risk-based recommendations that strengthen security, reduce cyber risk, and help organizations build resilient, compliant environments.
Why Work With Us
At PlutoSec, you'll work alongside experienced cybersecurity professionals on penetration testing, cloud security, malware analysis, and compliance projects. We foster continuous learning, innovation, and career growth while helping organizations stay secure against evolving cyber threats.
Gallery
.png)







