POSITION SUMMARY The Consultant, Penetration Testing is responsible for supporting the Consulting Services Team in delivering penetration testing services across a diverse portfolio of client engagements. This role operates as a flexible, deployable resource, contributing to multiple concurrent or sequential engagements based on business needs. This role requires proactive initiative to study, ask questions, and rapidly learn the organization’s solutions, methodologies, and delivery standards. Consultants must be comfortable transitioning between engagements, adapting quickly to new client environments, and delivering value immediately. Consultants focus on executing penetration tests, enhancing service quality, and improving project efficiency under the guidance of senior team members. They are expected to develop broad subject matter expertise, contribute to process improvements, and build trusted relationships across a variety of clients and internal teams. SPECIFIC JOB RESPONSIBILITIES Serve as a deployable consulting resource, supporting multiple client engagements across varying industries, with a focus on healthcare. Adapt quickly to new client environments, priorities, and team structures while maintaining high-quality delivery. Deliver offensive security services in the following areas: network, cloud, mobile application, web application, and AI penetration testing. Assist in the development of best practices, strategies, methodologies, tooling, and documentation/templates for use by the penetration testing team. Achieve high levels of client satisfaction on all engagements by meeting or exceeding client expectations set by engagement leaders and project managers. Work in collaboration with leadership to continue to update and mature team capabilities. Communicate findings and recommendations clearly to both technical and non-technical stakeholders. Collaborate with cross-functional teams and internal leadership to ensure seamless delivery across engagements. Manage competing priorities and transition effectively between assignments. Continue existing responsibilities: Draft reports and recommendations Support quality control Maintain client communication Contribute to internal process improvements Participate in knowledge sharing and training Achievement of utilization targets and client satisfaction scores. Adherence to company policies, procedures, and security requirements. Billable hours target: 1,768 hours annually (equivalent to 85% utilization) Perform other duties within the scope of the role as assigned. EXPERIENCE REQUIRED 1–3 years of consulting, cybersecurity, or related client-facing experience. Experience delivering offensive security services in at least one of the following areas, including network, cloud, mobile application, web application, and/or AI penetration testing and related technical security assessments is optional, and preferred. Experience supporting multiple projects or engagements simultaneously preferred. Demonstrable passion for offensive security: homelabbing, capture the flag (CTF) participation, bug bounty submissions, being involved in the security community, etc. A pattern of learning: you are constantly learning new technologies, exploring new tools, seeking certification, or reviewing exploit code. Problem solving: you are capable of solving problems independently. When an opportunity to develop a repeatable solution (e.g., a program, script, process) presents itself, you are eager to implement it. QUALIFICATIONS, SKILLS, & KNOWLEDGE Bachelor's degree in relevant discipline or relevant experience. Certifications preferred: PNPT, OSCP, OSEP, CRTO, GWAPT, CRTL. Knowledge of proprietary and open-source technical security testing tool suites (e.g., nmap, Nessus, Burp Suite, Wireshark, Kali Linux, etc.). Demonstratable analytic and problem-solving skills, especially with technical security analysis and client reporting. Ability to work without supervision on a variety of projects simultaneously and exercising good judgment and initiative to manage priorities. Strong written communication skills translating technical testing results into findings, observations, and recommendations for possible client remediation. Ability and willingness to learn about creating and executing repeatable work processes and procedures and learning techniques for planning, developing materials, and delivering training on technical subject matter and software products. Ability to manage competing priorities and adapt quickly between engagements. Familiarity with consulting methodologies and project delivery models. Demonstrates awareness or use of AI/automation tools to improve efficiency and delivery quality (optional, preferred). Ability to embrace Clearwater’s CLEAR core values ( C ommitment to Client Success, L ead with Accountability, Integrity & Collaboration, E xcellence in All That We Do, A dvance Colleague Success, R espect & Transparency) and culture. PROFESSIONAL DEVELOPMENT EXPECTATIONS Stay current on evolving threat landscapes, regulatory requirements, and cybersecurity best practices. Pursue and maintain industry certifications (OSCP, GWAPT, GMOB, CRTO, etc.). Expand knowledge across multiple cybersecurity domains to support diverse client needs. Contribute to internal innovation, tools, and delivery improvements. The base salary range for this role is $85,000-$100,000. Base salary is part of our total rewards package which also includes the opportunity for merit-based salary increases, eligibility for our 401(k) plan, medical, dental, vision, life and disability insurances and leaves provided in line with your work state. Our robust time-off policy includes flexible paid time off, 11 paid holidays, and paid sick time. Total compensation, including base salary to be offered, will depend on elements unique to each candidate, including applicable candidate experience, skills, education and other factors permitted by law. Disclaimer: The above statements are intended to describe the general nature and level of work being performed by people assigned to this position. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of colleagues in the role. All colleagues may be required to perform duties outside of their normal responsibilities from time to time, as needed. Clearwater is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. Please inform Clearwater/Redspin’s Recruiting team if you need any assistance completing any forms or to otherwise participating in the application process. Mental/Physical Requirements: Fast paced environment handling multiple demands. Must be able to exercise appropriate judgment as necessary. Requires a high level of initiative and independence. Excellent written and oral communication skills required. Requires the ability to use a personal computer for extended periods of time. Salary Description [update per job] Disclaimer: The above statements are intended to describe the general nature and level of work being performed by people assigned to this position. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of colleagues in the role. All colleagues may be required to perform duties outside of their normal responsibilities from time to time, as needed. Clearwater is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. Please inform Clearwater/Redspin’s Recruiting team if you need any assistance completing any forms or to otherwise participating in the application process. Mental/Physical Requirements: Fast paced environment handling multiple demands. Must be able to exercise appropriate judgment as necessary. Requires a high level of initiative and independence. Excellent written and oral communication skills required. Requires the ability to use a personal computer for extended periods of time.
Autonomous Penetration testing Lead Consultant
Allstate
Cybersecurity Intern, Penetration Testing Services - Summer 2027
Sensiba
Solutions Engineer, Penetration Testing
Prescient Security
Penetration Testing Lead - Vice President
Smbcgroup
Penetration Testing Team Lead
ECS Federal LLC
Senior Penetration Testing Engineer
All1033Allia