Penetration Tester

Remote
Full Time
Mid Level

About Malleum

Malleum is at the forefront of next-generation cyber defense, partnering with marquee clients across government, defense, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our teams design, build, and operate cutting-edge technologies and programs that protect the systems, data, and missions that matter most — from sovereign cyber initiatives to multi-domain threat operations supporting allied security frameworks.

If you want your work to have measurable impact at a national and international scale, join us. Malleum is where ambition meets mission.

The Opportunity

We're seeking a Penetration Tester who is highly committed to the craft. Working remotely and reporting to the CTO, in this position your mandate will be to assess the security posture of our clients by identifying and exploiting vulnerabilities in networks, applications, and systems. You’ll conduct controlled security assessments, execute attack simulations, and analyze security weaknesses. You’ll document findings and collaborate with colleagues and client teams to support remediation efforts. You’ll also contribute to analysis and reporting that provides actionable insights for improving defenses.

As an ideal candidate, you're skilled in pen testing and have exposure to adversarial emulation and custom exploit development. You’re a natural hacker with a founder’s mindset, eager to learn and collaborate, and prone to thrive in a startup environment.   

This is an outstanding opportunity to work with cutting-edge tech and tackle critical problems on high-stakes engagements.

What You'll Do

  • Conduct web, network, mobile, and API penetration tests to identify vulnerabilities. 
  • Support team assessments, simulating real-world attack scenarios. 
  • Develop and execute custom exploits, scripts, and attack chains. 
  • Conduct source code reviews for security weaknesses in applications. 
  • Assess cloud security in AWS, Azure, and GCP, as well as containerized environments like Docker and Kubernetes. 
  • Collaborate with blue teams, SOC analysts, and developers to remediate findings. 
  • Write detailed technical reports and present findings to technical and non-technical stakeholders. 
  • Stay updated on zero-day vulnerabilities, APT tactics, and emerging threats. 
  • Participate in CTFs, security research, and bug bounty programs to refine skills. 

What You Bring

  • 3-5 years of hands-on penetration testing experience. 
  • Proficiency in manual testing techniques beyond automated scanning. 
  • Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
  • Experience with Active Directory attacks, privilege escalation, and lateral movement. 
  • Skilled in the use of some or all of: Burp Suite, Nessus, Metasploit, Kali Linux.
  • Familiarity with scripting in Python, PowerShell, Bash, or Ruby.
  • Understanding of secure coding practices and DevSecOps principles. 
  • Excellent communication and interpersonal skills.
Nice-to-Haves
  • Experience in cloud security testing.
  • Knowledge of hardware hacking, IoT security, or reverse engineering. 
  • Familiarity with SOC operations, threat hunting, and incident response. 
  • Previous experience in bug bounty programs or published security research. 

Why Malleum

  • Work on programs with genuine national and allied security impact
  • Join a rapidly scaling firm with a flat, high-trust culture
  • Access to advanced labs, and emerging defensive technologies
  • Competitive compensation, performance incentives, and comprehensive benefits
  • Continuous learning budget, certification sponsorship, and clear paths to senior leadership

Malleum is an equal opportunity employer. We welcome applications from all qualified candidates and are committed to building a team that reflects the communities and missions we serve.

We are proud to accommodate individuals with disabilities throughout the recruitment and selection process. Please indicate your need for accommodations in your application.

 
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*