Offensive Security Consultant / Penetration Tester

Location: Full Time – Remote

Who this role is for: You are an experienced penetration tester who prefers deep manual work over scanner-driven checklists. You enjoy chaining findings, building proof-of-concept tooling, thinking like an adversary, and explaining technical risk clearly.

The person we’re looking for: You combine technical depth with humility, curiosity, clear communication, strong judgment, and a bias toward practical solutions.

What You’ll Do

  • Lead manual penetration tests across network, web/API, cloud, wireless, thick client, and enterprise environments
  • Execute objective-based red team and adversary simulation engagements when in scope
  • Develop custom proof-of-concept exploits, scripts, and tradecraft when existing tools are not enough
  • Produce clear reports with attack narratives, evidence, business impact, and remediation guidance
  • Contribute to HALOCK methodology, tooling, lab work, research, and deliverables.
  • Participate in project kickoff and report delivery meetings
  • Mentor by example through sound judgment, clean execution, and professional communication

What You Bring

  • 5-7+ years of hands-on experience in penetration testing, offensive security consulting, or red team operations
  • Depth in at least one major domain, such as network, Active Directory, web/API, cloud, or red teaming
  • A skills-based certification or equivalent practical proof of ability
  • Proficient with common industry tools and C2 frameworks
  • Scripting or coding ability useful for automation, tooling, or exploitation
  • Working knowledge of PTES, OWASP, MITRE ATT&CK, and related offensive security references
  • Strong client-facing communication and ability to deliver with minimal supervision

Bonus Points

  • Previous experience conducting penetration testing in a consulting capacity
  • Experience testing cloud, identity, EDR-protected endpoints, or mature enterprise networks
  • Ability to translate offensive security findings into compliance-relevant risk and remediation guidance
  • Experience with malware development, C2 framework enhancements, and EDR evasion
  • Desire to contribute to HALOCK’s blog and/or speak at industry conferences on occasion

Why Strong Testers Join HALOCK

At HALOCK Security Labs, we’re building an offensive security team for serious testers: technical, curious, practical, and focused on work that matters.

Our work is not tool-heavy checkbox testing. We think like adversaries, pursue meaningful attack paths, and turn technical evidence into decisions clients can act on.

What you can expect: remote-first work, challenging client environments, paid training and certifications, conference opportunities, experienced teammates, and room to improve methodology.

How We Work

We work as a high-trust, low-ego team that shares techniques, debriefs hard findings, challenges assumptions, and helps each other improve.

You will have room to go deep technically, improve methodology, contribute to research and tooling, and deliver work clients can rely on.

About Us

HALOCK Security Labs is a full-service information security consulting firm in Schaumburg, Illinois. Since 1996, we have provided technical security expertise and strategic advisement across penetration testing, red teaming, malware defense, incident response, risk, and compliance.

HALOCK offers competitive compensation and benefits, including bonus potential, paid training and certifications, health and dental coverage, 401(k), long-term disability, conference attendance, and more.

Ready to apply? If this sounds like the work you want to do and the teammate you want to be, send your resume and a brief note about a challenging penetration test, red team engagement, exploit chain, or technical problem you worked through.

Disclosures

  • HALOCK is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees.
  • Full background checks are performed, with consent, on all successful candidates before employment offers can be extended.
  • US citizens and Green Card holders, EAD and TN are encouraged to apply. We are unable to sponsor H1 candidates at this time.
  • No 3rd parties please. Only individuals need apply.