Senior Penetration Tester Needed

Job ID: 39917798

Budget: $15 – $25 USD

I’m ready to bring an experienced penetration tester onto our security team for an in-depth engagement that zeroes in on internal network security, specifically Active Directory. The main mission is to uncover and prove credential-harvesting paths inside our AD environment, then document practical remediation steps that my blue team can act on immediately.

Scope
• Map the internal attack surface, moving from initial foothold through to credential exposure inside AD.
• Use industry-standard tooling—Cobalt Strike, Metasploit, Nmap, Nessus, Burp Suite—and any custom Python, Go, C, or JavaScript scripts you already rely on.
• Demonstrate credential-harvesting techniques (Kerberoasting, AS-REP roasting, DCSync, etc.) and show how they transition into privilege escalation or lateral movement.
• Provide clear, reproducible evidence: screenshots, command logs, payload samples, and suggested hardening measures.

Deliverables
1. Executive-level summary outlining business impact.
2. Technical report with step-by-step attack narrative, exploited vulnerabilities, and remediation guidance.
3. Proof-of-concept code or scripts used during testing.
4. Debrief session (live or recorded) to walk the team through findings.

Acceptance Criteria
• All major AD credential-harvesting vectors are attempted and documented.
• Exploits are validated on non-production clones first, then selectively on production with prior approval.
• Reports are delivered within two weeks of kickoff and are immediately actionable.

If you hold certifications such as OSCP, OSCE, CEH, or CISSP and have at least five years in red teaming or penetration testing, I’d like to see how you can help us turn identified weaknesses into concrete security improvements.