Remote (United States)
1 month agoJob Overview
Job Type
Salaried, Full-TimePay
Not disclosedJob description
- Location:
- Remote (United States)
- Work arrangement:
- Remote
Role Summary
Netrio is a leading MSP in North America, specializing in IT solutions for small- to mid-market enterprises. We serve over 1,000 clients across industries with services including managed IT, cybersecurity, cloud, connectivity, voice, and custom application development.
We deliver offensive security assessments to clients across a range of industries. This entry-level role focuses on internal and external network penetration testing. You’ll work alongside senior testers on live client engagements from the start.
Responsibilities
- Conduct external network penetration tests: attack surface enumeration, service and application discovery, credential attacks, and exploitation of exposed services within an approved scope
- Conduct internal network penetration tests: network and host enumeration, Active Directory reconnaissance and attack path analysis, credential harvesting and reuse, privilege escalation, and lateral movement
- Validate vulnerability scanner output and eliminate false positives through manual testing
- Capture reproducible evidence for every finding
- Perform remediation retesting
- Operate strictly within the authorized scope and rules of engagement on every engagement
Requirements
- 1-3 years in IT, systems or network administration, SOC, or a related field, or demonstrable hands-on offensive security skill through labs and personal projects
- Solid networking fundamentals: TCP/IP, DNS, SMB, LDAP, HTTP/S
- Working knowledge of Windows and Active Directory, including common misconfigurations
- Comfortable in a Linux terminal
- Familiarity with standard tooling such as Nmap, Nessus, Metasploit, Impacket, BloodHound, Responder, Hashcat, and Burp Suite
- Basic scripting in Python, PowerShell, or Bash
- Strong written communication and a professional client-facing demeanor
Preferred Qualifications
- OSCP, PNPT, CPTS, eJPT, or CRTP — held or in progress
- Documented lab or CTF work you can discuss in detail
- Prior systems or network administration experience
- Exposure to cloud or web application testing
- Role:
- Associate Penetration Tester
- Job Type:
- Salaried, Full-Time