Sr. Penetration Tester / Ethical Hacker

September 7, 2026

Job Description

Company: Reactforce

Location: AZ, US

Company Description Reactforce is a resilience-first cybersecurity firm that applies more than 25 years of combined business and technology experience to protect public and private organizations. The company delivers tailored risk management, incident response, vCISO services, penetration testing, compliance support, and managed security services. Reactforce focuses on strengthening operational resilience and reducing cyber risk through practical, outcome-driven engagements. Team members collaborate with diverse clients, addressing real-world threats across multiple industries. The environment emphasizes professionalism, technical excellence, and continuous learning.

Role Description This is a remote contract role for a Sr. Penetration Tester / Ethical Hacker. The role involves planning and executing advanced penetration tests against web, mobile, API, network, and cloud environments to identify exploitable weaknesses and security gaps. Day-to-day responsibilities include performing red team exercises, developing and executing attack scenarios, documenting findings, and providing clear, actionable remediation guidance to technical and non-technical stakeholders. The Sr. Penetration Tester will conduct in-depth reverse engineering and malware analysis as needed, collaborate with incident response and vCISO teams, and help refine testing methodologies and tooling. The role also entails staying current with emerging threats, exploit techniques, and security best practices while supporting continuous improvement of Reactforce’s services.

Qualifications

– Strong cybersecurity foundation, including secure architecture principles, threat modeling, and familiarity with common attack frameworks (e.g., MITRE ATT&CK).
– Expertise in Application Security, including secure code review, web and mobile application testing, and API security assessment.
– Hands-on Red Teaming skills, including adversary emulation, lateral movement, privilege escalation, and stealthy operations in complex environments.
– Proficiency in Reverse Engineering and Malware Analysis, including disassembly, debugging, and behavior analysis of binaries and malicious code.
– Experience with penetration testing tools and frameworks (e.g., Burp Suite, Metasploit, Nmap, Cobalt Strike, Kali or similar toolsets).
– Strong scripting or programming skills (e.g., Python, PowerShell, Bash, or Go) to develop custom tools, payloads, and automation.
– Ability to produce clear, concise, and actionable reports and communicate technical findings to both technical and business audiences.
– Relevant certifications such as OSCP, OSCE, OSEP, GXPN, GREM, or equivalent practical experience are highly beneficial.
– Experience working in consulting or service-based environments and collaborating with cross-functional cybersecurity teams.
– Commitment to ethical standards, confidentiality, and continuous professional development.

Source: LinkedIn