Catapult Federal Services logo

Senior Penetration Tester (Internal / External / Wireless / Cloud)

Catapult Federal Services

Remotesenior$85/hrPosted 2h ago

Job description

IT

New York, NY Contract Sep 3, 2026

Senior Penetration Tester (Internal / External / Wireless / Cloud)

Location: Remote

Role Type: Contract

About Our Client

Our client is a cybersecurity consulting firm specializing in offensive security services, helping enterprise, state/local government and education (SLED), and federal organizations identify and close security gaps before real attackers can exploit them. Their engagement scope spans internal, external, wireless, and cloud environments, and continues to expand into emerging areas like AI and LLM security testing. [Additional detail on company history/age, headquarters or office locations, and mission/values not provided โ€” happy to add if you share it.]

Job Description

We're looking for a Senior Penetration Tester who can independently scope, lead, and execute offensive security engagements across internal, external, wireless, and cloud environments. This is a hands-on, engagement-ownership role โ€” you'll be the lead technical resource on fixed-scope, time-boxed assessments, from initial scoping calls through testing, reporting, and executive-level debriefs.

The ideal candidate has deep, real-world offensive security experience, is comfortable operating autonomously with minimal oversight, and can communicate findings clearly to both technical teams and executive stakeholders. Experience with cloud hardening assessments and emerging AI/LLM security testing is a strong plus, as engagement scope continues to expand into these areas.

Duties And Responsibilities

  • Independently scope, plan, and lead internal, external, wireless, and cloud penetration testing engagements end-to-end

  • Conduct internal network penetration tests, including Active Directory attack path analysis and privilege escalation

  • Perform external/perimeter penetration testing to identify internet-facing vulnerabilities and attack surface exposure

  • Execute wireless security assessments (WPA2/WPA3, rogue AP detection, network segmentation testing)

  • Conduct cloud hardening/hardiness assessments across AWS, Azure, and/or GCP โ€” identifying misconfigurations, IAM exposure, and attack surface risks

  • Lead client scoping calls to define engagement objectives, rules of engagement, and testing boundaries

  • Execute fixed-scope, time-boxed engagements autonomously, managing timelines and deliverables independently

  • Produce clear, detailed, client-ready penetration testing reports with actionable remediation guidance

  • Deliver executive debriefs, translating technical findings into business risk and impact for non-technical stakeholders

  • Stay current on emerging attack techniques, tools, and threat landscape developments across traditional and cloud environments

  • Where applicable, support AI readiness/guardrail assessments, including LLM security testing, prompt injection/red-teaming, and model governance framework evaluation

Required Experience/Skills

  • 6+ years of experience in offensive security, with demonstrated lead/senior-level engagement ownership

  • Required certification (one or more): OSCP, OSCE/OSEP, GPEN or GWAPT, or OSWP (wireless)

  • Proven track record independently scoping and executing internal, external, and wireless penetration tests end-to-end

  • Hands-on experience conducting cloud hardening/hardiness assessments (AWS/Azure/GCP) โ€” misconfigurations, IAM exposure, attack surface review

  • Strong background in Active Directory attack paths, perimeter/external testing, and wireless security assessments (WPA2/3, rogue AP, segmentation)

  • Experience leading engagements for enterprise, SLED, or federal clients

  • Demonstrated history of client-facing report writing and executive-level debriefs

  • Proficiency with industry-standard offensive security tools: Burp Suite, Metasploit, Cobalt Strike, Nmap, BloodHound, Aircrack-ng/Kismet

  • Able to work autonomously on fixed-scope, time-boxed engagements with minimal oversight

  • Comfortable leading scoping calls and client debriefs directly

  • Strong written and verbal communication skills across technical and executive audiences

Nice-to-Haves

  • Experience with AI readiness/guardrail assessments โ€” LLM security testing, prompt injection/red-teaming, model governance frameworks

  • Additional advanced certifications beyond the required set (e.g., holding more than one of OSCP/OSCE/OSEP/GPEN/GWAPT/OSWP)

  • Experience testing federal or highly regulated environments (e.g., FedRAMP, StateRAMP, CMMC-adjacent engagements)

  • Familiarity with purple team or adversary emulation frameworks (e.g., MITRE ATT&CK-aligned engagements)

  • Prior experience mentoring junior penetration testers or contributing to methodology/playbook development

Education

[Not provided โ€” let us know if a degree or equivalent experience requirement applies]

Pay & Benefits Summary

  • Pay: $85/hr

Call-to-Action

Ready to lead high-impact offensive security engagements from scoping to executive debrief? Apply now!

Keywords

Penetration Testing | Offensive Security | Cloud Security | Red Team | OSCP | Active Directory | Wireless Security | Remote Contract