Penetration Testing Analyst 3 (Red Team) - Remote
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Sophos is seeking an experienced and motivated Penetration Testing Analyst 3 to join our Red Team. The Sophos Red Team identifies and exploits vulnerabilities in client environments, applying information security threat intelligence to uncover weaknesses real-world adversaries would target.
As a Penetration Testing Analyst 3, you will act as the point of contact for testing readiness, coordinating tasks, timelines, and communication between business, client, and project teams. Responsibilities include escalating issues to management, taking ownership of new challenges, and adding value to job accomplishments.
You will focus on either application security (web application penetration testing, mobile, API testing) or network security (vulnerability assessments, external/internal penetration tests), using both off-the-shelf and internally developed tools to execute manual testing for advanced attacks.
Key Responsibilities:
- Coordinate activities, documentation, readiness schedules, and information between business, clients, and project teams.
- Act as the point of contact and communicate testing readiness status to all participants.
- Use project management tools to monitor key tasks, timelines, and status.
- Report and escalate issues to management as needed.
- Take ownership of new challenges and explore opportunities to add value.
- Conduct application security assessments (web, mobile, API) or network penetration testing assessments (external/internal pen tests).
- Produce and deliver vulnerability and exploit information to clients in professional security assessment reports.
- Conduct client conference calls, including readiness, troubleshooting, kick-off, high/critical findings notifications, and close-out reviews.
- Perform proactive research to identify and understand new threats, vulnerabilities, and exploits.
- Conduct exploitation testing using off-the-shelf or self-developed tools and document findings for client remediation.
- Excel as both a self-directed individual contributor and as a member of a larger team.
What You Will Bring:
- 3+ years of experience in Information Security.
- Excellent client-facing and internal communication skills, both written and verbal.
- Ability to learn quickly and thrive in a high-energy team environment.
- Professional, proactive attitude and strong team player.
- Solid organizational skills, including attention to detail and multitasking.
- Minimum of 3 years of experience with penetration testing.
- Minimum of 3 years of experience with at least one of the following: Nmap, Metasploit, Kali Linux, Burp Suite.
- Desirable:
- Experience with Nmap Scanning.
- Understanding of web application authentication methods.
- Experience with Linux.
- Understanding of networking and appliances (routers, load balancers, firewalls, WAF, IDS/IPS, web content filter/proxy).
- Understanding of tools to validate network access with a penetration testing platform.
- Offensive certifications such as CEH, WAPT, GPEN, GWAPT, GAWN, OSCP, etc.
- Knowledge of operating systems administration and internals (Microsoft Windows/Linux).
- Understanding of TCP/IP networking at a technical level.
- Experience with various application attack vectors, security test processes, and strong knowledge of common vulnerabilities (i.e., OWASP Top 10).
- Good troubleshooting skills, technical communication skills, both written and verbal; good analytical and problem-solving skills.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Sophos
Explore Top Companies in this Space
DeleteMe
Software Development / Data Protection / Cybersecurity
Patch My PC
Software Development / IT Management / Cybersecurity / Enterprise Software
Kapres Technology
IT Consulting / Cybersecurity / Software Development
Resilinc
Supply Chain Management / Risk Management / Artificial Intelligence / Enterprise Software
Sophos
View Company ProfileSophos (operating at sophos.com) is a security software and hardware company engineered for cybersecurity. Founded in Not specified by Not specified and headquartered in Oxford, Sophos takes a prevention-first approach to security by stopping threats earlier — blocking ransomware, phishing, and credential-based attacks before they become business-disrupting events. Under the hood, Sophos is powered by agentic AI and elite human expertise, detecting, investigating, and neutralizing threats. This allows more than 40,000 customers worldwide to defeat cyberattacks and achieve superior cybersecurity outcomes. Backed by Not specified.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.




