Fractional Penetration Tester
Bishop Fox
| Company | Bishop Fox |
| Category | Uncategorised |
| Location | U.S. Remote |
| Remote | Remote |
| Employment | Not stated |
| Level | Not stated |
| Salary | USD 130–200 |
| Posted | 6 May 2026 |
| Last verified | 12 Aug 2026 |
| Source | The employer's own careers page (company_site) |
Description
Penetration Tester - Contract
Location: U.S. Remote
Position Type: Contract (1099 Independent Contractor)
Overview
Bishop Fox is looking for experienced contract penetration testers with a primary focus in web application security and strong secondary expertise in cloud, mobile, source code, network, or AI/LLM security. You'll work on a range of projects, from short-term assessments to longer-term program engagements with well-established clients.
Responsibilities
• Identify vulnerabilities, validate risk, develop creative solutions, and clearly communicate findings and remediation guidance to both technical and executive stakeholders
• Plan, conduct, and manage web application penetration tests
• Assess vulnerabilities and develop exploits across diverse targets
• Serve as a trusted advisor to help clients understand risk and make informed security decisions
• Work alongside US and internationally-based teams supporting clients across multiple industries
Required Experience
• 5+ years of experience planning, conducting, and managing web application penetration tests
• Deep understanding of application security fundamentals, OWASP Top 10, common vulnerabilities, and secure development best practices
• Experience assessing vulnerabilities and developing exploits across diverse targets
• Strong understanding of system and network security, authentication protocols, security protocols, and applied cryptography
• Ability to communicate complex technical findings clearly and provide practical remediation guidance to technical and executive audiences
Preferred Experience
Deep experience in at least one of the following:
• Cloud Security - Experience assessing AWS cloud environments, including technologies such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambda
• Mobile Application Security - Experience testing iOS and/or Android applications, including mobile application architecture, API communication, data storage, authentication flows, and common mobile security vulnerabilities
• Source Assisted Application Assessments - Experience evaluating applications across multiple layers, including source code, APIs, infrastructure, and integrations. Strong proficiency in Golang is highly preferred, along with familiarity in languages such as Python, Ruby, PowerShell, Java, and JavaScript
• Network Security - Experience with network and system exploitation, including modern tactics, techniques, and procedures such as C2 frameworks, EDR bypass, privilege escalation, password cracking, and lateral movement
• AI/LLM Security - Experience assessing non-deterministic security controls
Employment Details
• Employment Type: Independent contractor (1099)
• Sponsorship: Not eligible for any form of employment sponsorship. Applicants must be legally authorized to work in the United States without requiring visa sponsorship now or in the future
• Location Requirement: Must be located in the United States
• Background Check: All new hires must pass a background check as a condition of employment