Rooted
Back to jobs
ER
Open role

Echelon Risk + Cyber

Junior Penetration Tester

Remote, United States· REMOTE

Operator+ signal

About the role

You carry out security assessments on client systems within an agreed scope and timeframe. For the first few months you work alongside a senior tester; after that you run your own engagements. Roughly half the job is testing and half is writing: each finding needs clear reproduction steps, evidence and an explanation of the real business impact, because that is what allows the client to fix it.

What you will do

  • Test within an agreed scope and stay inside it
  • Document every finding with steps, evidence and real impact
  • Retest fixes and say plainly whether they closed the issue

What they ask for

  • Hands-on practice: labs, CTFs and bug bounty all count
  • Comfortable with Burp Suite and a scripting language
  • Can explain an attack path to somebody who is not technical

Nice to have

  • eJPT, PNPT or equivalent
  • Public write-ups
  • A disclosed finding

What applying with Rooted means

This role accepts applications with Rooted context. Instead of sending only a resume, you can attach a verifiable credential with your proofs, rank, and technical evidence.

Your application includes your Rooted credential: rank, verified proofs, and supporting evidence.

You can read this role without an account. To apply you need a Rooted credential.

This role is curated by Rooted. Rooted is not the hiring company unless explicitly stated. The hiring company is Echelon Risk + Cyber. Confirm the final details with the original source or during the application process.

Posted 2026-08-13