
Senior Penetration Tester
BPM LLPPosted 5/15/2025

Senior Penetration Tester
BPM LLP
Job Location
Salary Range
Job Summary
BPM is seeking a Senior Penetration Tester to join their team in the Pacific Northwest. The ideal candidate has at least 5 years of hands-on experience with security, a solid understanding of manual penetration testing principles, and excellent communication skills. They will be responsible for conducting cyber security assessments, uncovering vulnerabilities, and advising clients on remediation strategies. BPM offers a total rewards package, well-being resources, professional development opportunities, and flexible work arrangements. The company values people who put others first, critical problem solvers, self-starters, and lifelong learners. As a Senior Security Consultant, you will have the opportunity to make a positive difference for clients, colleagues, and communities while growing in your career and work-life balance.
Job Description
Responsibilities
- Perform detailed manual penetration tests of networks, applications, and systems
- Conduct reconnaissance through open source intelligence (OSINT) on target clients to locate exposed data
- Leverage collected data and provided client target details to successfully socially engineer client employees via emails and phone calls
- Perform red team engagements to gain access to client specified resources through covert tests that blend multiple attack vectors
- Document security vulnerabilities in-depth during client engagements
- Effectively communicate findings and provide remediation guidance to both technical and non-technical stakeholders
- Drive internal team innovation, collaboration, and advancement through professional development time
Requirements
- A minimum of five years hands-on experience with security
- A minimum of five years performing system administration, development, or a similar background in technology
- Documented oral and written communication skills including complex technical document preparation
- Strong understanding of network and application protocols (e.g., TCP, UDP, SMB, HTTP, FTP)
- Deep knowledge of how software works and interacts at various layers
- Demonstrates adaptive and critical thinking skills to solve unique and challenging problems
- Ability to use multiple operating systems with high proficiency (e.g., Windows, Linux, macOS)
- Understanding of enterprise technology and experience with Active Directory
- Strong comfort with languages such as Bash, Python, Go, and PowerShell
- Experience with web development technologies (e.g., React, HTML, JavaScript, etc.)
- Experience with tools commonly used to perform security testing (e.g., Nmap, Burp Suite, evilginx, hashcat, Metasploit, Nessus, impacket, C2 frameworks, nuclei, gophish, Dradis, Ghostwriter, etc.)
- Familiarity with industry security standards and frameworks (e.g., NIST SP 800-53, NIST CSF, MITRE)
- Must be able to pass criminal background checks
- Must be eligible to work in the United States without sponsorship
- Ability to thrive in a team environment that operates without ego
Bonus Qualifications
- Incident response or digital forensics (DFIR) experience
- Bachelor's degree in Computer Science or related technical field
- Security certifications such as OSCP, CISSP, Security+, or similar
- Experience with iOS or Android Mobile application development
- Highly Proficient in at least one programming language such as C++, Java, .NET, Rust, Python, Go
- Experience managing and deploying red team infrastructure
- Have developed tooling or published security research for the greater security community
- Experience with CIS Benchmarks and how to audit against them
- Physical security experience & a desire to travel to client locations