This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client’s perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defense strategies. Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities—it tests the customer’s entire security posture and defense-in-depth strategy. In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments.
Job Responsibility
Deliver Rapid7’s Vector Command Continuous Red Teaming service
Evaluate large external attack surfaces to identify vulnerabilities that enable initial access
Collaborate closely with a team of Red Team operators, participating in daily meetings
Analyze, develop, and exploit N-day and newly released zero-day vulnerabilities
Identify novel attacks through black-box evaluation of customer web applications
Develop and maintain positive relationships with clients
Participate in industry conferences and professional organizations
Create additional value for clients through continual insights and consultative advice
Translate technical concepts and convey them to non-security personnel
Mentor and coach junior staff
Meet professional practice standards and demonstrate exceptional skill in core service areas
Requirements
5+ years in an active technical security role & 4+ years Penetration Testing Consulting experience
Expert knowledge of Modern penetration testing tools and methods
Network and web-based application security concepts
Windows/Linux/UNIX internals
Exploit research and development
Experience using multiple interpreted languages (Ruby, Python, PHP, etc.) and compiled languages (Java, C, C++, Assembly, etc.)
Technical competencies, including previous technical consulting experience
High quality report writing and peer reviewing
Strong knowledge of common regulatory structures and obligations and common I.T. governance
The ability to effectively lead teams of penetration testers while on engagements
Be comfortable explaining findings and recommendations to technical and non-technical audiences including C-Level and Board briefings