Penetration Tester, full-time, remote, paying up to $120,000 a year, open to candidates in any location on the map.
The listing says freelance, but this one runs as a full-time position once you look past the title. The core of the job is simple to describe and hard to do well: get into systems the same way a real attacker would, before an actual one gets the chance. Clients pay for that gap between "we think we're secure" and "we've actually confirmed it," and closing that gap is most of what this role does.
What the work involves
An exposed internal API that returns full customer records to anyone who happens to guess the right endpoint is the kind of thing this role is built to catch. Not through luck, but through methodically working through an application the way someone with bad intentions eventually would, given enough time. That process rarely looks dramatic from the outside. It's mostly patient, structured probing, punctuated by the occasional moment where something that shouldn't work actually does.
- Probe applications, systems, and the networks connecting them for openings a real attacker could actually use, working through each target methodically rather than running a single automated pass
- Write up findings clearly enough that an engineering team can act on them without needing a translator
- Recommend specific fixes, not just a list of problems, so the people closing the gaps know where to start
A finding is only as useful as the report attached to it. Naukri Mitra has seen plenty of skilled testers undersell their work with a rushed write-up that leaves an engineering team guessing at severity or root cause. Technical skill gets someone in the door during an interview, but writing is what actually fixes a vulnerability once the engagement is over.
Certifications and technical skills
OSCP tends to open more doors than any other single credential in this field, though CEH is treated as an acceptable equivalent by most employers, this one included. Beyond the certification itself, the role leans on a solid grounding in how network security actually holds together end-to-end, scripting ability to build or adapt exploits when an off-the-shelf tool doesn't quite fit, and real comfort with tools like Burp Suite and Metasploit. None of these need to be equally strong on day one, though a wide gap in any single area tends to show up quickly once real engagement work starts.
Ethical hacking know-how underlies all of it, but the certification and the tool list are really just proxies for something harder to measure directly: whether someone can think like an attacker without losing sight of the fact that the goal is to help, not just to break things. That distinction sounds obvious stated plainly, but it shows up constantly in how a tester chooses what to chase and how far to push a given technique.
Background that fits
A bachelor's degree is the baseline, and either a computer science background or a program focused specifically on cybersecurity satisfies it. The specific major matters less here than in many technical roles, and a candidate from a less conventional academic path isn't automatically screened out if the practical experience holds up. Three years of genuine, sanctioned testing experience is the minimum expected, working on real environments with real stakes rather than only lab exercises or capture-the-flag competitions. Someone who's spent that time building a track record of legitimate, documented assessments is going to stand out more than someone with a longer resume but thinner hands-on time.
Pay and benefits
This role pays up to $120,000 annually. On the benefits side, expect retirement plan matching, standard health coverage, paid time off, and a dedicated allowance for certifications and continuing training. That last piece matters more here than in most jobs, since staying sharp in this field means constantly testing new techniques against new defenses, and a certification earned five years ago says less about current skill than a recent one does.
What the work is actually like
Engagements come in waves rather than a steady drip. A test against a client's application might run hard for two weeks, then leave a quieter stretch to write up findings and follow up on questions from the engineering team as they fix them. That rhythm suits some people better than others, and it's worth being honest with yourself about which one you are before signing on.
Scope matters more here than it might seem from the outside. Straying outside an agreed testing boundary, even accidentally, isn't a minor slip in this line of work; it's the difference between a legitimate assessment and something that could cause real legal trouble for everyone involved. Discipline around scope is treated as seriously as technical skill during interviews. A candidate who can't articulate why staying inside the agreed boundary matters, beyond "because the contract says so," usually isn't the right fit regardless of how strong their exploit skills are.
Not every finding turns out to matter in the end. A vulnerability that looks alarming on paper sometimes turns out to be unreachable in practice once the full environment is understood, and part of the job is being honest about that instead of inflating a report to make it look more impressive. Clients trust that honesty more over time than they trust a report full of critical-severity findings that don't hold up under closer questioning.
Applying
Send a resume along with your current certifications and, if you're able to share one without violating any client confidentiality, a sanitized example of a past finding or report. A candidate who can walk through their own methodology clearly tends to interview better here than one who can only list the tools they've used. Applications are reviewed on a rolling basis, with no fixed cutoff date attached to this posting. Someone actively studying for OSCP right now, with a solid track record otherwise, shouldn't hold off on applying until the exam results come back.