HumanResourcely.
FreeJob description · mid

Ethical Hacker job description.

An ethical hacker conducts authorized penetration tests and vulnerability assessments to identify security weaknesses before malicious actors can exploit them. They simulate real-world attacks against networks, applications, and systems, then document findings and recommend remediation steps, working closely with security and IT teams to strengthen the organization's overall security posture.

8 responsibilities·5 required + 3 preferred·US + AU
Ready to send

The Ethical Hacker job description · $29

The full editable .docx — role summary, 8 worked responsibilities, qualifications, and skills, formatted for your letterhead. Delivered to your inbox within 24 hours — usually instantly.

Preview
HumanResourcely · Vol. I
Ethical Hacker — Job Description

Role: Ethical Hacker    Reports to: Information Security Manager

An ethical hacker conducts authorized penetration tests and vulnerability assessments to identify security weaknesses before malicious actors can exploit them. They simulate real-world attacks against networks, applications, and systems, then document findings and recommend remediation steps, working closely with security and IT teams to strengthen the organization's overall security posture.

1. Key responsibilities
  • Conduct authorized penetration tests against networks, applications, and systems
  • Perform vulnerability assessments and identify security gaps
  • Simulate real-world attack techniques to test defensive controls
Full document with email opt-in
Composition

What's inside the document.

01Role summary

One-paragraph plain-English explanation of the role's outcome and scope.

02Responsibilities

8 responsibilities phrased the way the work is actually done.

03Required qualifications

5 qualifications a candidate must have to perform on day 30.

04Preferred qualifications

3 qualifications that would make a candidate excellent in year two.

05Skills

6 skill chips you can copy directly into your ATS.

06Reporting line

Information Security Manager

What you receive

A complete document set.

  • Word document (.docx) — fully editable
  • PDF — signature-ready
  • Google Docs — one-click copy to your Drive
  • 12 months of updates to this document
  • Commercial-use licence for internal and client work
Responsibilities at a glance

The work, not the title.

  • Conduct authorized penetration tests against networks, applications, and systems
  • Perform vulnerability assessments and identify security gaps
  • Simulate real-world attack techniques to test defensive controls
  • Document findings, exploit paths, and severity ratings in detailed reports
  • Recommend remediation steps and validate fixes after implementation
  • Use industry-standard tools for scanning, exploitation, and analysis
  • Stay current on emerging threats, exploits, and attack techniques
  • Ensure all testing activity complies with legal and ethical guidelines and scope agreements
Qualifications

Required — and what would make a candidate excellent.

Required
  • Bachelor's degree in computer science, information security, or equivalent experience
  • Strong knowledge of networking, operating systems, and web application security
  • Hands-on experience with penetration testing tools and methodologies
  • Understanding of common security frameworks and attack techniques
  • Strong analytical skills and clear technical report writing
Preferred
  • CEH, OSCP, or equivalent security certification
  • Experience with red team or adversary simulation engagements
  • Scripting skills in Python, Bash, or similar languages
Skills
Penetration testingVulnerability assessmentNetwork securityExploit analysisSecurity reportingRisk analysis
How to use this template

Eight steps from download to publish.

  1. 01Open the Ethical Hacker job description in Word or your one-click Google Docs copy.
  2. 02Replace placeholders for company name, reporting line, and location with your specifics.
  3. 03Tighten the summary to one paragraph that names the team's outcome, not just the role.
  4. 04Edit the responsibilities to match the actual scope of the seat — aim for 6 to 8 items, not 12.
  5. 05Separate required qualifications from preferred. Required is what a candidate must have to do the work on day 30; preferred is what would make them excellent in year two.
  6. 06Add salary range guidance using BLS, Payscale, or your own band data — do not copy generic figures.
  7. 07Have the hiring manager and one peer read it. Cut anything that wouldn't survive a candidate question.
  8. 08Publish to your ATS, intranet, and external careers page.
When to use this template

The right document at the right moment.

Use this Ethical Hacker job description any time you are opening or reopening a seat at this level. The mid band sets the calibration — copy the document, tighten it to your specific scope, and circulate to the hiring panel before the first interview.

The reporting line (Information Security Manager) and skills list are starting points. Override either if your org structure or stack differs from the norm — the template is a draft, not a contract.

FAQ

Honest answers before you download.

How is an ethical hacker different from a security analyst?
An ethical hacker actively attempts to breach systems under authorized engagement rules, while a security analyst more broadly monitors, detects, and responds to threats.
What certifications should I look for when hiring an ethical hacker?
Certifications such as CEH or OSCP are common industry signals, though hands-on penetration testing experience and a clean track record matter just as much.
Legal note

This Ethical Hacker job description is a professionally drafted starting point for your hiring process and is not legal advice. Hiring practice varies by jurisdiction (e.g. pay-transparency laws differ across US states and AU jurisdictions). Adapt this document for your specific location and have employment counsel review any clauses you add before publishing. Salary varies by region, employer type, and experience. Reference BLS or current industry surveys for ranges. Full disclaimer.