Convergence Networks

Penetration Tester

Convergence Networks  •  $130k - $150k/yr  •  Milwaukie, OR (Remote)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Job Location: Milwaukie, OR 97222
Salary Range: $130,000.00 - $150,000.00 SalaryConvergence Networks is Portland’s leading Managed Services Firm. Our philosophy is to foster strong relationships with fellow teammates and clients, create an unrivaled work environment, and provide an outstanding customer experience. We are looking to expand our team with the addition of a Penetration Tester (SE), but before we get into what the job is, let’s start with why you would want to work with us!
- First and foremost, our culture: We have worked very hard to create a culture of unity, transparency, and trust. Our leadership team wants you to be successful at Convergence, and we will do anything we can to support your personal and professional growth.
- We encourage a culture of diversity, and welcome people of all different backgrounds and walks of life to join our team. We have found that having people with a variety of experiences helps add to our success.
- We offer a competitive salary with profit sharing bonuses, and a great PTO plan with 8 additional paid holidays each year.
- An education and certification reimbursement program is also available so we can help you move up the ranks.
- A company-matched 401k plan that is designed to help you meet your retirement goals.
- Some of the absolute best health insurance plans available for you and your family (including free healthcare plans!).
- Outstanding teammates; we’re very selective to make sure we have the best staff available for you to work alongside!
- Many teambuilding and company events throughout the year so you can get to know your teammates on a more personal level, as well as kick back and have some fun (families are oftentimes included as well).
- Relaxed work environment; we know you’ll be in the office a fair amount of time, and we want you to enjoy yourself and experience what it’s like to be a part of the Convergence family.
As for the position, our SE serves as an integral part of our technical services team. In this role you will perform intermediate and advanced offensive security tasks that support the delivery of client security services, including vulnerability assessments, penetration testing, and social engineering engagements. This is a client-facing role that requires the ability to independently deliver standard penetration testing engagements while collaborating with fellow Security Engineers and Analysts and providing technical assistance and direction to Security Analysts.
This is an intermediate position that requires strong knowledge of networking, operating systems, identity services, common enterprise technologies, and offensive security concepts such as vulnerabilities, exploitation, post-exploitation, and social engineering. Qualified SEs are expected to plan, execute, document, and communicate penetration testing work professionally across a range of Convergence services.

Summary and Responsibilities:
- The primary responsibilities of the SE are to plan and execute technical security tasks that serve as critical elements of the security services we deliver to our clients.
- Penetration Testing & Security Assessments
- - Conduct Open-Source Intelligence (OSINT) gathering and reconnaissance activities against target organizations.
- - Independently perform standard external and internal network penetration testing engagements.
- - Assess Microsoft Active Directory environments, including enumeration, privilege escalation, credential abuse, lateral movement, and common attack paths.
- - Conduct authenticated and unauthenticated vulnerability assessments against client environments.
- - Validate vulnerabilities through manual testing and, when authorized, controlled exploitation and post-exploitation techniques on Windows and Linux systems.
- - Conduct standard web application penetration testing and support advanced application testing based on experience and engagement requirements.
- Specialized Security Assessments
- - Depending on experience and specialization, perform wireless security assessments against corporate wireless infrastructure.
- - Depending on experience and specialization, execute physical penetration testing engagements to evaluate physical security controls.
- - Depending on experience and specialization, conduct cloud penetration testing and security assessments within Microsoft Azure and Amazon Web Services (AWS) environments.
- - Depending on experience and specialization, perform advanced social engineering or adversary-simulation assessments to evaluate organizational security controls.
- Security Consulting & Client Engagement
- - Provide security consulting and technical guidance to clients.
- - Lead project kickoff meetings and communicate engagement objectives, scope, and methodologies.
- - Present findings, explain security risks, and deliver detailed engagement debriefs to both technical and non-technical stakeholders.
- - Develop and maintain strong client relationships through professional communication and subject matter expertise.
- - Assist clients with remediation planning and security improvement initiatives.
- Reporting & Documentation
- - Produce professional penetration testing reports that clearly document vulnerabilities, business impact, exploitation details, and remediation recommendations.
- - Ensure all reports meet internal quality standards and industry best practices.
- - Maintain accurate project documentation and engagement notes throughout the testing lifecycle.
- Operational Responsibilities
- - Assess and scope customer environments to determine testing requirements and engagement complexity.
- - Maintain and secure penetration testing infrastructure, tools, and testing equipment.
- - Manage assigned projects, tickets, and deliverables while meeting established deadlines.
- - Collaborate with internal teams when required and contribute to continuous improvement initiatives.
What Does Success Look Like:
- Deliver high-quality penetration testing engagements on time and within scope.
- Produce clear, actionable, and client-focused security reports.
- Build trusted relationships with clients through professionalism and technical excellence.
- Continuously improve offensive security skills and contribute to the growth of the security practice.
- Demonstrate a commitment to lifelong learning and professional development.
What skills do I need to be a successful SE?
- Technical Skills
- - Experience using Kali Linux or comparable penetration testing distributions.
- - Knowledge of common network ports, protocols, and network topologies.
- - Hands-on familiarity with Microsoft Active Directory environments, common attack paths, and associated security controls.
- - Working knowledge of Microsoft 365 security controls and cloud security concepts; deeper Azure/AWS testing experience is desirable for specialized engagements.
- - Experience working with exploitation frameworks such as Metasploit.
- - Understanding of post-exploitation, privilege escalation, credential access, and lateral movement techniques on Windows and Linux systems.
- - Ability to perform vulnerability analysis, validate findings through manual testing, and distinguish exploitable security issues from scanner output and false positives.
- - Ability to independently plan and execute standard internal and external network penetration tests within an approved scope and rules of engagement.
- Professional Skills
- - Strong written and verbal communication skills.
- - Ability to translate technical security findings into business-relevant risk discussions.
- - Excellent problem-solving and analytical thinking abilities.
- - Ability to think creatively and approach challenges from multiple perspectives.
- - Self-motivated with the ability to work independently.
- - Strong time management and organizational skills.
- - Ability to collaborate effectively with internal teams and external stakeholders.

QualificationsWhat are the qualifications I need to have?
- High school diploma or equivalent.
- 3+ years of relevant information technology, cybersecurity, or offensive security experience, with demonstrated hands-on penetration testing or security assessment experience.
- Advanced understanding of computer and networking concepts, services, and protocols, including TCP/IP, the OSI networking model, DNS, e-mail flow, operating systems, firewall technologies, network switching, and identity services.
- Ability to communicate effectively with both technical and non-technical client stakeholders, orally and in writing.
- Strong documentation and technical reporting skills, including the ability to explain vulnerability evidence, business impact, exploitation details, and remediation recommendations.
- Industry-recognized cybersecurity certification or equivalent demonstrated professional experience. Security+ or a higher-level cybersecurity certification may satisfy this requirement.
- Demonstrated practical penetration testing competency through professional experience, a technical assessment, or a hands-on offensive security certification is required.
- Foundational or junior practical penetration testing certifications are acceptable evidence of offensive security fundamentals, such as:
- - Practical Junior Penetration Tester (PJPT)
- - eLearnSecurity Junior Penetration Tester (eJPT)
- - Equivalent hands-on entry-level offensive security certification
- A junior-level certification alone does not establish intermediate-level competency. Candidates relying on a junior credential should also demonstrate sufficient hands-on experience to independently conduct standard client penetration testing engagements.
- Must possess or be willing to obtain within the first 12 months of employment a professional-level practical penetration testing certification such as the Practical Network Penetration Tester (PNPT), Offensive Security Certified Professional (OSCP/OSCP+), CREST Registered Penetration Tester (CRT), or an approved equivalent.
- Equivalent combinations of professional experience, demonstrated technical capability, education, certifications, labs, research, or other offensive security experience may be considered.
What qualifications would help set me apart from other applicants?
- Associate degree or higher in Information Technology, IT Assurance, or Information Security (Cybersecurity).
- Certified Ethical Hacker (CEH), CEH Practical, or CEH Master.
- CompTIA PenTest+ or other supporting cybersecurity/offensive security certifications.
- Professional or advanced offensive security certifications such as PNPT, OSCP/OSCP+, CREST CRT, GPEN, advanced OffSec or CREST certifications, or other recognized practical penetration testing credentials.
- Specialized certifications in red teaming/adversary simulation (including RTO/CRTO), web application testing, Active Directory exploitation, cloud security testing, wireless security, or social engineering.
- Advanced knowledge and experience with key software platforms and utilities such as nmap, Nessus, and Kali Linux.
How would we describe the work environment?
- Typical working hours for the SE vary, but will typically include Monday through Friday, 8 AM – 5 PM, as well as various off-hours work during projects.  You will be typically working about 40-45 hours per week.
- In office, hybrid, and remote options available, we will work with you to accommodate your preferred work style. This position will occasionally require onsite travel for company meetings, visits to client sites, and assessments. Must be willing to travel if remote.
- This position requires standing, walking, sitting, using hands, seeing, reaching, talking, and hearing. May need to lift and/or move up to 50 pounds occasionally.
- Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Some after-hours work will be required. Work likely can be completed remotely.
How often will I get formal feedback on how well I'm doing?
- 90-day, six-month, and annual (12-month) performance reviews, with yearly reviews being a performance and salary review.
- Bi-weekly 1:1 meeting with your Manager.
- You and your Manager will set performance review goals.
How often will Convergence get feedback on how we are doing for you?
- You will receive a 60-day check-in after your start date to ensure that we have correctly set you up for success; how was our onboarding process? Did we show you everything you needed to know to do your job well, or did we miss something? You will have an opportunity to share this so we can course-correct as needed and refine our process for future employees.
- You will also receive an annual stay interview to offer unfiltered, honest feedback in a 100% safe environment. We use this data to make sure we keep doing what is going well for our Team and find ways to keep improving ourselves.
- Your Team Leader will have regularly scheduled 1:1 meeting to discuss how things are going, so you'll never be left wondering.
- The Leadership Team regularly takes employees out to lunch, even if you don't report to them! We want all employees to have a healthy relationship with leadership, and what better way than to break bread.
- 100% open-door policy to all Leadership and Human Resources. Feel free to walk in anytime and share your feedback.
Convergence Networks

About Convergence Networks

Convergence Networks is one of North America's leading Managed Services & Security Providers. We are focused on preparing our customers for the future that’s just around the bend: a complex environment in which users access data through multiple applications on multiple devices. The only way forward is an identity-driven security strategy, protecting your data wherever you venture.

We’ve always thought security first, not security as an add-on. Our team works with you to build an integrated, consistent, and robust security posture centered around Microsoft’s industry-leading solutions. We attract incredibly capable people from across the globe who work with our customers as strategic partners to drive results in the uncharted territory of tomorrow’s technology landscape.

At Convergence Networks, you’ll find a culture built on trust and autonomy. We’re a place for people who elevate those around them. How do you know you’ll go far here? You bring drive, accountability, and a passion for charting your course – together.

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
US & Canada
Year Founded
2000
Social Media