Jobiglo

No results.

Penetration Tester

Bright

Remote
Remote 🇬🇧 English
Python JavaScript OWASP Top 10 DAST SAST CI/CD pipelines reverse engineering malware analysis network security operating system internals authentication encryption

Job description

About the role

Bright Security is seeking a remote Penetration Tester to join its security team. You will lead security assessments of web applications, APIs, business logic, and LLM‑based components, combining manual expertise with automated tooling. The role collaborates closely with product, development, and security engineers to embed findings into the company’s developer‑centric workflows.

Key responsibilities

  • Plan and execute security assessments on web applications, APIs, business logic, and LLM‑based components using manual and automated techniques.
  • Identify, validate, and document vulnerabilities, reproduce issues with engineering teams, and propose remediation steps.
  • Develop and maintain test methodologies, contribute to security tooling, and participate in red‑team exercises.
  • Collaborate with product, development, and security teams to embed findings into Bright’s developer‑centric workflows.
  • Stay up‑to‑date with emerging threats, exploitation techniques, and industry best practices.

Required profile

  • Strong application security knowledge, including secure coding concepts and OWASP Top 10 web and API vulnerabilities.
  • Hands‑on experience with penetration testing, red‑team operations, and offensive security reporting.
  • Proficiency in reverse engineering, malware analysis, and understanding of exploit payloads and evasion.
  • Solid fundamentals in network security, operating‑system internals, authentication/authorization, and encryption.
  • Ability to produce clear technical reports and communicate risk to both technical and non‑technical audiences.
  • Comfort working independently in a remote, distributed team across time zones.

Required skills

  • Python (scripting/automation)
  • JavaScript or similar programming language
  • OWASP Top 10 knowledge
  • DAST and SAST tools
  • CI/CD pipeline integration
  • Reverse engineering and malware analysis
  • Network security concepts
  • Operating‑system internals
  • Authentication and encryption basics

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Bright.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 month ago

Expires 1 week from now

41 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Bright