Senior Penetration Tester (Part-Time/Contractor)

Netragard
Netragard

Boston, MA, USA · Remote

Posted on Jul 29, 2026
About the RoleNetragard is currently seeking a Senior Penetration Tester on a Part-Time/Contractor basis to join our team of passionate cybersecurity professionals.This role involves performing manual penetration testing of our customers’ information technology systems including their external/internal infrastructure, web, and mobile applications, etc.We are looking for an equally passionate individual who thinks differently about problems and looks for new angles in challenging situations.Location:Boston/RemoteResponsibilities• Conduct manual penetration testing for a variety of systems, such as, web, mobile, API, and infrastructure (internal, external, and wireless)• Plan and execute social engineering campaigns and physical penetration tests• Identify, understand, and exploit vulnerabilities to gain and expand access to remote systems• Document and communicate technical findings verbally and in a written format to the appropriate stakeholders/teams.• Assist in retesting security vulnerabilities that have been remediated and updating the report with remediation test findings.• Provide remediation recommendations• Assist with building, hardening, and maintaining systems used for testing• Stay up to date on cutting edge security topics and new attack vectors• Assist with pre-sales scoping to prospective clients• Review reports for depth and accuracy• Communicate with customers throughout testing engagement• Act as a source of direction, training, and guidance for less experienced staff• Conduct research and publish articles on the latest cybersecurity newsYou must have the following skills and experience:• 5+ years of experience performing penetration tests• 5+ years of experience consulting• 1+ Industry leading qualification (OSCP/OSWE/OSCE, CRTO, CISSP, CREST, PNPT, etc.)• Good written and verbal communication skills (in English)• Report writing experienceNice to have:• Contribution to open-source projects (i.e., send us your GitHub)• Security related blog• Cybersecurity conference presentations• Participation and/or write-ups of CTFs• Bug Bounty profileNB: No recruitment agencies.