Career Opportunities

Penetration Tester

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

Get to know the Security Services Team


We are the team that turns complex security requirements and compliance frameworks into infrastructure and services that actually work. Moving fast and taking true end-to-end ownership, our team spans three core functions: Cloud Security Engineering, where we design hardened AWS, Azure, and GCP environments, write Terraform baselines, and fix failing controls to meet frameworks like SOC 2, ISO 27001, CMMC, and FedRAMP; Penetration Testing, where we run disciplined offensive assessments across networks, apps, cloud, and AI/LLM systems to catch vulnerabilities before adversaries do; and Vulnerability Management, where we continuously prioritize, patch, and validate risk reduction across the client footprint. We do not hide behind process or just point out gaps. We step in, build solutions, and deliver real security posture improvements with minimal disruption.


What makes this team special isn't just our technical depth; it is how we back each other up. Our strongest engineers and assessors are the ones building reusable modules, writing custom tools, jumping into channels to unblock teammates, and mentoring without being asked. From early-stage startups to regulated enterprises, you will work directly with clients, take on real ownership early, and be surrounded by people who want to see you get good. If you enjoy solving tough security problems and want to be part of a team that is scrappy enough to move fast but seasoned enough to get it right, you will be in good company here.



The Opportunity

We are seeking a Penetration Tester to join our growing cybersecurity team. In this role, you will assess the security of applications, networks, and systems through structured penetration testing and vulnerability assessments. You will help identify weaknesses, document findings, and provide actionable recommendations to strengthen clients’ security defenses.


What you'll do

  • Execute comprehensive penetration tests across web, mobile, network, and system environments to uncover, exploit, and validate critical infrastructure and application vulnerabilities.
  • Produce high-fidelity technical reports mapping out exploit impact and proof-of-concept chains, translating complex risk metrics into actionable remediation roadmaps for clients.
  • Partner directly with client engineering teams to guide post-assessment remediation, troubleshoot implementation blocks, and systematically verify the integrity of deployed fixes.
  • Engineer custom testing scripts, automation tools, and offensive methodologies to continuously expand vulnerability discovery coverage and testing precision.
  • Deploy tactical social engineering simulations, including targeted phishing and pretexting campaigns, to rigorously audit human security awareness and organizational defenses.
  • Support active incident response loops by providing offensive technical expertise, investigating compromise vectors, and accelerating threat containment pipelines.
  • Own the supporting client experience by maintaining transparent communications, gathering environmental prerequisites, and breaking down testing footprints into clear, business-friendly milestones.
  • Track the evolving threat landscape to continuously integrate cutting-edge exploit techniques, active vector changes, and defensive counter-measures into live assessment playbooks.


Who you are

  • Active offensive security operator - Command a proven history of executing structured penetration tests, vector mapping, and threat validation across complex application, network, and system environments.
  • Master of offensive frameworks - Deployed industry-standard testing platforms, exploitation architectures, and reporting frameworks to uncover hidden systemic security vulnerabilities.
  • Surgical exploit and validation engineer - Exploited, classified, and cataloged multi-tier security vulnerabilities, providing clear remediation roadmaps to client engineering teams to securely validate system fixes.
  • Precision technical author - Formulated high-fidelity assessment documentation, exploit chain proofs, and detailed impact reports that translate complex threat data into highly structured, actionable guidance.
  • High-impact security diplomat - Articulated tactical risk scenarios, testing footprints, and remediation expectations with professional clarity to both deep technical infrastructure teams and executive client stakeholders.
  • Social engineering and automation developer - Engineered custom testing scripts, targeted phishing simulations, and pretexting campaigns to audit human security awareness and expand overall assessment coverage.
  • Autonomous remote operator - Command an advanced local testing station fully optimized for heavy virtual machine deployment, maintaining peak operational velocity during standard US Eastern Time working hours.
  • Validated offensive security specialist - Hold or actively pursue high-value technical designations such as OSCP, CEH, or equivalent credentials that demonstrate a rigorous commitment to offensive security practices.


What help you succeed

  • Advanced cloud security auditing - Direct execution of cloud infrastructure penetration tests, container security evaluations, and environment configuration audits within AWS, GCP, or Azure.
  • Integration of GRC compliance frameworks - Practical alignment of technical vulnerability data to satisfy the automated audit and evidence requirements of SOC 2, GDPR, or HIPAA.
  • Commercial tenure in high-velocity startups - Years spent scaling offensive security workflows, handling rapid client delivery timelines, and adapting to shifting priorities within fast-growth tech environments.
  • Incident containment and threat training - Direct support of active incident response containment loops, or the design and execution of technical employee threat awareness initiatives.


What we offer

  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.


What you'll need to thrive

  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.


Hiring and Selection Process

  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.


Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.



Engagements

Philippines

Compartir en:

Condiciones del servicioPrivacidadCookiesDesarrollado por Rippling