Bishop Fox is a leading security consulting firm serving the Fortune 1000 and high-tech startups. We protect our clients by finding vulnerabilities and building defenses before the attackers can break bad. From critical infrastructure to credit cards; social media to mobile games; flight navigation systems to frozen waffle factories — we’re right there hacking away.
We’re seeking remote senior penetration testers to join our team – and help us build a more secure world.
Who You Are and What You’ll Do
You are a born penetration tester; you see problems (and solutions) in everything. You instinctively know your way around source code. You’ve plundered apps and pillaged networks (legally, of course). You have a passion for hacking that goes beyond a career – it’s a way of life for you. At this point, you may have accumulated a few disclosures, blog posts, or talks under your belt. if given the chance, you could probably Hack the Gibson.
With Bishop Fox, your responsibilities would include testing smart devices before they hit the market, hacking networks, and reversing software. Some days, you’ll be red teaming wireless networks and participating on social engineering engagements. Other days, you’ll be analyzing source code and building threat models. Every day at Bishop Fox, you’ll be learning.
As a consultant, you’ll solve challenging technical problems and build creative solutions. As a trusted advisor, you’ll provide your expert opinion to help our clients navigate difficult business decisions. And as a senior penetration tester, you’ll lead teams on one-of-a-kind engagements, mentor co-workers, and contribute significantly to the advancement of our consulting practice.
Why Bishop Fox
Bishop Fox offers competitive salary, generous benefits, flexible schedules, and negotiable travel. If you’re looking for opportunities to grow professionally, this is the place. You’ll work alongside some of the most talented and experienced security consultants in the industry.
We have a casual workplace environment, but we‘re consummate professionals.
Your Education and Experience
Our wants are simple: be good at and, most importantly, love what you do. Here’s a list of qualities we’re looking for, but don’t think that you need them all:
- Vulnerability assessment
- Penetration testing and code review
- Understanding security fundamentals and common vulnerabilities (e.g., OWASP Top Ten)
- 2 - 5 years of application security experience
- More than 3 years of security consulting experience
- Additional experience in IT, security engineering, system and network security, authentication and security protocols, and applied cryptography
- Scripting/programming skills (e.g., Python, Ruby, Java, JS, etc.)
- Network and web-related protocol knowledge (e.g., TCP/IP, UP, IPSEC, HTTP, HTTPS, routing protocols)
- Federal and industry regulations understanding (e.g., PCI, SOX, GLBA, ISO 17799, HIPAA, CA1386)
- Strong communication skills (i.e., written and verbal)
- CISSP, OSCP/E, GWAPT, GPEN, or GXPN certifications are helpful, but not a necessity
- Advanced relevant academic training is a definite bonus
- The self-discipline to work independently; as a remote worker, the same will be asked of you as all Bishop Fox team members.
Candidates across the country (or even the world) are welcome to apply.
Interested? Drop us a line today.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.
About Bishop Fox
About us Founded in 2005, Bishop Fox is a global information security consulting firm, serving as trusted advisors to the Fortune 1000, financial institutions, and high-tech startups. Our mission is to secure our clients and their business. Each member of our team brings expertise and perspective to the table. We put our background in government intelligence, the Fortune 100, Big 4 consulting, and global security to work for our clients. For more than a decade, we have authored best-selling security books, been cited in leading journals like Security Week and Dark Reading; been quoted in newspapers like USA Today; and been interviewed on local, national, and international television. As presenters at conferences such as Black Hat, DEF CON, BlueHat, and RSA; we continually put ourselves at the forefront of the security industry.