Penetration Tester
About Workstreet
At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the Security Services Team
We are the team that turns complex security requirements and compliance frameworks into infrastructure and services that actually work. Moving fast and taking true end-to-end ownership, our team spans three core functions: Cloud Security Engineering , where we design hardened AWS, Azure, and GCP environments, write Terraform baselines, and fix failing controls to meet frameworks like SOC 2, ISO 27001, CMMC, and FedRAMP; Penetration Testing , where we run disciplined offensive assessments across networks, apps, cloud, and AI/LLM systems to catch vulnerabilities before adversaries do; and Vulnerability Management , where we continuously prioritize, patch, and validate risk reduction across the client footprint. We do not hide behind process or just point out gaps. We step in, build solutions, and deliver real security posture improvements with minimal disruption.
What makes this team special isn't just our technical depth; it is how we back each other up. Our strongest engineers and assessors are the ones building reusable modules, writing custom tools, jumping into channels to unblock teammates, and mentoring without being asked. From early-stage startups to regulated enterprises, you will work directly with clients, take on real ownership early, and be surrounded by people who want to see you get good. If you enjoy solving tough security problems and want to be part of a team that is scrappy enough to move fast but seasoned enough to get it right, you will be in good company here.
The Opportunity
We are seeking a Penetration Tester to join our growing cybersecurity team. In this role, you will assess the security of applications, networks, and systems through structured penetration testing and vulnerability assessments. You will help identify weaknesses, document findings, and provide actionable recommendations to strengthen clients’ security defenses.
What you'll do
-
Execute comprehensive penetration tests across web, mobile, network, and system environments to uncover, exploit, and validate critical infrastructure and application vulnerabilities.
-
Produce high-fidelity technical reports mapping out exploit impact and proof-of-concept chains, translating complex risk metrics into actionable remediation roadmaps for clients.
-
Partner directly with client engineering teams to guide post-assessment remediation, troubleshoot implementation blocks, and systematically verify the integrity of deployed fixes.
-
Engineer custom testing scripts, automation tools, and offensive methodologies to continuously expand vulnerability discovery coverage and testing precision.
-
Deploy tactical social engineering simulations , including targeted phishing and pretexting campaigns, to rigorously audit human security awareness and organizational defenses.
-
Support active incident response loops by providing offensive technical expertise, investigating compromise vectors, and accelerating threat containment pipelines.
-
Own the supporting client experience by maintaining transparent communications, gathering environmental prerequisites, and breaking down testing footprints into clear, business-friendly milestones.
-
Track the evolving threat landscape to continuously integrate cutting-edge exploit techniques, active vector changes, and defensive counter-measures into live assessment playbooks.
Who you are
-
Active offensive security operator - Command a proven history of executing s