Jobs · Information Technology

Offensive Security Engineer — Fully Remote

CoTrain · United States · 2 wk ago
RemoteRemoteInformation Technology$5k–$10k/moPart-time

CoTrain is hiring on behalf of a team that needs an experienced offensive security specialist for a scoped, fully authorized engagement to test their CRM and related systems.

About the role

The goal: demonstrate, under controlled conditions, the ability to access client data; identify real attack paths; and deliver a clear report with evidence and remediation steps so the team can close the gaps. All work is performed strictly within a written statement of work, rules of engagement, and legal authorization — limited sample data only, with no unauthorized exfiltration or disruption.

Responsibilities

  • Perform an authorized penetration test of the CRM and related systems within an agreed scope
  • Identify and demonstrate real attack paths across credentials, permissions, APIs, and identity
  • Show, under controlled conditions, where client data could be accessed
  • Document findings with clear evidence and reproducible steps
  • Deliver actionable, prioritized remediation guidance the team can implement to close the gaps

Requirements

  • Proven experience in offensive security, penetration testing, or red teaming
  • Strong grasp of identity, access control, API, and permission-based attack paths
  • Experienced testing SaaS/CRM or similar business-critical systems
  • Rigorous about scope, authorization, and responsible disclosure — you operate strictly within rules of engagement
  • Excellent reporting skills: you translate technical findings into clear, actionable remediation for both engineers and leadership

Nice to have

  • Relevant certifications (OSCP, OSCE, GPEN, GWAPT, or similar)
  • Cloud security experience (AWS / GCP / Azure)
  • Familiarity with common CRM platforms and their integration/API surfaces

Pay

$4,500–$10,000/month, based on experience and scope.

Engagement terms

This is a remote, contract role fixed to a defined statement of work. The engagement is controlled, legal, and fully authorized, governed by a signed SOW, rules of engagement, and NDA. Candidates must be comfortable working within strict, documented boundaries.

Similar jobs

Security Engineer | Remote

CodeGeniusRecruitUnited States· 2 wk ago
RemoteInformation Technology$80–$90/hrapply on candidateportal.ceipal.com