Coalfire Logo

Coalfire

Consultant, Penetration Tester - Compliance Security

Posted 17 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Mid level
Remote
Hiring Remotely in United States
Mid level
Conduct penetration testing and security assessments across various platforms, simulate cyberattacks, advise clients on security best practices, and mentor junior staff.
The summary above was generated by AI

About Coalfire


Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and U.K., and we support clients around the world.


But that’s not who we are – that’s just what we do.

 

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.


Position Summary

 

Join a collaborative and dynamic team of cybersecurity professionals to conduct cutting-edge penetration testing across a wide range of technologies and environments. As a Consultant, you’ll play a key role in identifying vulnerabilities, simulating real-world cyberattacks, and helping our clients strengthen their security posture.

 

Your day-to-day will include internal and external network penetration testing, application security assessments (browser-based, API, mobile), cloud environment testing, social engineering engagements, and wireless assessments.

What You’ll Do

  • Perform security assessments across various platforms and technologies
  • Simulate sophisticated cyberattacks to assess and improve client defenses
  • Advise clients on technical security and compliance best practices
  • Manage your own testing priorities and deliver high-quality work on time
  • Collaborate with internal teams - PMs, QA, sales, and other consultants to deliver exceptional client service
  • Create and maintain testing methodologies, documentation, and processes
  • Write detailed, high-quality reports for both technical and executive stakeholders
  • Scope and lead penetration testing engagements from start to finish
  • Help resolve escalations during active assessments
  • Mentor junior team members and contribute to a positive team environment
  • Support the team’s success by contributing to KPIs, innovation, and knowledge sharing

What You’ll Bring

  • Bachelor's degree (four-year college or university) or equivalent combination of education and work experience
  • 3+ years of hands-on experience in network and/or application penetration testing
  • Proficiency with scripting languages such as Python, PowerShell, Shell, or Ruby
  • Familiarity with security frameworks (e.g., PCI, HIPAA, FedRAMP, HITRUST, or FISMA)
  • 1–3 years of experience in IT security audit and/or compliance roles
  • Strong technical foundation in networks, servers, workstations, and applications
  • Experience working in a consulting or client-facing role (minimum 3 years)
  • Strong communication and presentation skills - able to interface with both technical and non-technical stakeholders
  • Willingness to travel occasionally (up to 10%)

  • You should have solid proficiency in at least one of the following areas:

  • Compliance-Driven Penetration Testing (e.g., PCI, FedRAMP)
  • Cloud Penetration Testing (e.g., AWS, Azure, GCP)
  • Network/Active Directory Penetration Testing
  • Application (Web/API/Mobile/Thick) Penetration Testing
  • Secure Code Review
  • Hardware or IoT Testing
  • Container Security Testing
  • AI or ML System Testing

  • What Sets You Apart

  • Proven ability to manage time and juggle multiple tasks under tight deadlines
  • Strong consulting presence - can lead client meetings, kickoff calls, and present findings clearly
  • Excellent report writing skills - capable of drafting both technical detail and executive summaries
  • Continuous learning mindset - actively pursuing certifications and keeping up with threat landscapes

Why You’ll Want to Join Us


At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.


Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.


At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, our Human Resources team at [email protected].

Top Skills

AWS
Azure
GCP
Penetration Testing
Powershell
Python
Ruby
Shell

Similar Jobs

Yesterday
Remote
Hybrid
United States
Mid level
Mid level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
The Product Security Consultant opens and manages security product deployments, advises on best practices, and automates solutions for customers. Responsibilities include documentation, scripting, and providing pre-sales support.
Top Skills: AWSGoogle Cloud PlatformGrcIdsIpsAzurePowershellPythonSIEMSQL
Yesterday
Easy Apply
Remote
2 Locations
Easy Apply
157K-217K Annually
Senior level
157K-217K Annually
Senior level
Artificial Intelligence • Fintech • Machine Learning • Social Impact • Software
As a Senior Offensive Security Engineer, you'll build and lead the Offensive Security program, test Upstart's controls, and collaborate with various security teams.
Top Skills: AWSCi/CdEksKubernetesmacOSOktaPython
Yesterday
Remote
USA
110K-180K Annually
Senior level
110K-180K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Sr. Cloud Red Team Engineer emulates threat actors in cloud environments, assesses security, and enhances CrowdStrike's Falcon security capabilities.
Top Skills: .NetAWSC/C++GdbGhidraGoIdaRustWindbg

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account