Associate Penetration Tester
netrio
Remote (United States)
Posted Aug 26, 2026
- Full-time
- Service Delivery
Job description
About the Role We deliver offensive security assessments to clients across a range of industries. This entry-level role focuses on internal and external network penetration testing. You’ll work alongside senior testers on live client engagements from the start. Responsibilities • Conduct external network penetration tests: attack surface enumeration, service and application discovery, credential attacks, and exploitation of exposed services within an approved scope • Conduct internal network penetration tests: network and host enumeration, Active Directory reconnaissance and attack path analysis, credential harvesting and reuse, privilege escalation, and lateral movement • Validate vulnerability scanner output and eliminate false positives through manual testing • Capture reproducible evidence for every finding • Perform remediation retesting • Operate strictly within the authorized scope and rules of engagement on every engagement Required Qualifications • 1-3 years in IT, systems or network administration, SOC, or a related field, or demonstrable hands-on offensive security skill through labs and personal projects • Solid networking fundamentals: TCP/IP, DNS, SMB, LDAP, HTTP/S • Working knowledge of Windows and Active Directory, including common misconfigurations • Comfortable in a Linux terminal • Familiarity with standard tooling such as Nmap, Nessus, Metasploit, Impacket, BloodHound, Responder, Hashcat, and Burp Suite • Basic scripting in Python, PowerShell, or Bash • Strong written communication and a professional client-facing demeanor Preferred Qualifications • OSCP, PNPT, CPTS, eJPT, or CRTP — held or in progress • Documented lab or CTF work you can discuss in detail • Prior systems or network administration experience • Exposure to cloud or web application testing Netrio is a leading MSP in North America, specializing in IT solutions for small- to mid-market enterprises. We serve over 1,000 clients across industries with services including managed IT, cybersecurity, cloud, connectivity, voice, and custom application development.