| Location | Milwaukie, OR |
Convergence Networks is Portland's leading Managed Services Firm. Our philosophy is to foster strong relationships with fellow teammates and clients, create an unrivaled work environment, and provide an outstanding customer experience. We are looking to expand our team with the addition of a Penetration Tester (SE), but before we get into what the job is, let's start with why you would want to work with us!
As for the position, our SE serves as an integral part of our technical services team. In this role you will perform intermediate and advanced offensive security tasks that support the delivery of client security services, including vulnerability assessments, penetration testing, and social engineering engagements. This is a client-facing role that requires the ability to independently deliver standard penetration testing engagements while collaborating with fellow Security Engineers and Analysts and providing technical assistance and direction to Security Analysts.
This is an intermediate position that requires strong knowledge of networking, operating systems, identity services, common enterprise technologies, and offensive security concepts such as vulnerabilities, exploitation, post-exploitation, and social engineering. Qualified SEs are expected to plan, execute, document, and communicate penetration testing work professionally across a range of Convergence services.
Summary and Responsibilities:
The primary responsibilities of the SE are to plan and execute technical security tasks that serve as critical elements of the security services we deliver to our clients.
Penetration Testing & Security Assessments
Conduct Open-Source Intelligence (OSINT) gathering and reconnaissance activities against target organizations.
Independently perform standard external and internal network penetration testing engagements.
Assess Microsoft Active Directory environments, including enumeration, privilege escalation, credential abuse, lateral movement, and common attack paths.
Conduct authenticated and unauthenticated vulnerability assessments against client environments.
Validate vulnerabilities through manual testing and, when authorized, controlled exploitation and post-exploitation techniques on Windows and Linux systems.
Conduct standard web application penetration testing and support advanced application testing based on experience and engagement requirements.
Specialized Security Assessments
Depending on experience and specialization, perform wireless security assessments against corporate wireless infrastructure.
Depending on experience and specialization, execute physical penetration testing engagements to evaluate physical security controls.
Depending on experience and specialization, conduct cloud penetration testing and security assessments within Microsoft Azure and Amazon Web Services (AWS) environments.
Depending on experience and specialization, perform advanced social engineering or adversary-simulation assessments to evaluate organizational security controls.
Security Consulting & Client Engagement
Provide security consulting and technical guidance to clients.
Lead project kickoff meetings and communicate engagement objectives, scope, and methodologies.
Present findings, explain security risks, and deliver detailed engagement debriefs to both technical and non-technical stakeholders.
Develop and maintain strong client relationships through professional communication and subject matter expertise.
Assist clients with remediation planning and security improvement initiatives.
Reporting & Documentation
Produce professional penetration testing reports that clearly document vulnerabilities, business impact, exploitation details, and remediation recommendations.
Ensure all reports meet internal quality standards and industry best practices.
Maintain accurate project documentation and engagement notes throughout the testing lifecycle.
Operational Responsibilities
Assess and scope customer environments to determine testing requirements and engagement complexity.
Maintain and secure penetration testing infrastructure, tools, and testing equipment.
Manage assigned projects, tickets, and deliverables while meeting established deadlines.
Collaborate with internal teams when required and contribute to continuous improvement initiatives.
What Does Success Look Like:
What skills do I need to be a successful SE?
Technical Skills
Experience using Kali Linux or comparable penetration testing distributions.
Knowledge of common network ports, protocols, and network topologies.
Hands-on familiarity with Microsoft Active Directory environments, common attack paths, and associated security controls.
Working knowledge of Microsoft 365 security controls and cloud security concepts; deeper Azure/AWS testing experience is desirable for specialized engagements.
Experience working with exploitation frameworks such as Metasploit.
Understanding of post-exploitation, privilege escalation, credential access, and lateral movement techniques on Windows and Linux systems.
Ability to perform vulnerability analysis, validate findings through manual testing, and distinguish exploitable security issues from scanner output and false positives.
Ability to independently plan and execute standard internal and external network penetration tests within an approved scope and rules of engagement.
Professional Skills
Strong written and verbal communication skills.
Ability to translate technical security findings into business-relevant risk discussions.
Excellent problem-solving and analytical thinking abilities.
Ability to think creatively and approach challenges from multiple perspectives.
Self-motivated with the ability to work independently.
Strong time management and organizational skills.
Ability to collaborate effectively with internal teams and external stakeholders.
What are the qualifications I need to have?
High school diploma or equivalent.
3+ years of relevant information technology, cybersecurity, or offensive security experience, with demonstrated hands-on penetration testing or security assessment experience.
Advanced understanding of computer and networking concepts, services, and protocols, including TCP/IP, the OSI networking model, DNS, e-mail flow, operating systems, firewall technologies, network switching, and identity services.
Ability to communicate effectively with both technical and non-technical client stakeholders, orally and in writing.
Strong documentation and technical reporting skills, including the ability to explain vulnerability evidence, business impact, exploitation details, and remediation recommendations.
Industry-recognized cybersecurity certification or equivalent demonstrated professional experience. Security+ or a higher-level cybersecurity certification may satisfy this requirement.
Demonstrated practical penetration testing competency through professional experience, a technical assessment, or a hands-on offensive security certification is required.
Foundational or junior practical penetration testing certifications are acceptable evidence of offensive security fundamentals, such as:
Practical Junior Penetration Tester (PJPT)
eLearnSecurity Junior Penetration Tester (eJPT)
Equivalent hands-on entry-level offensive security certification
A junior-level certification alone does not establish intermediate-level competency. Candidates relying on a junior credential should also demonstrate sufficient hands-on experience to independently conduct standard client penetration testing engagements.
Must possess or be willing to obtain within the first 12 months of employment a professional-level practical penetration testing certification such as the Practical Network Penetration Tester (PNPT), Offensive Security Certified Professional (OSCP/OSCP+), CREST Registered Penetration Tester (CRT), or an approved equivalent.
Equivalent combinations of professional experience, demonstrated technical capability, education, certifications, labs, research, or other offensive security experience may be considered.
What qualifications would help set me apart from other applicants?
How would we describe the work environment?
How often will I get formal feedback on how well I'm doing?
How often will Convergence get feedback on how we are doing for you?