HumanResourcely.
FreeJob description · mid

Penetration Tester job description.

A Penetration Tester simulates cyberattacks against networks, applications, and systems to identify security vulnerabilities before malicious actors can exploit them. They conduct authorized testing engagements, document findings, and recommend remediation steps to strengthen an organization's overall security posture.

8 responsibilities·4 required + 3 preferred·US + AU
Ready to send

The Penetration Tester job description · $29

The full editable .docx — role summary, 8 worked responsibilities, qualifications, and skills, formatted for your letterhead. Delivered to your inbox within 24 hours — usually instantly.

Preview
HumanResourcely · Vol. I
Penetration Tester — Job Description

Role: Penetration Tester    Reports to: Security Manager or CISO

A Penetration Tester simulates cyberattacks against networks, applications, and systems to identify security vulnerabilities before malicious actors can exploit them. They conduct authorized testing engagements, document findings, and recommend remediation steps to strengthen an organization's overall security posture.

1. Key responsibilities
  • Plan and execute authorized penetration tests on systems and networks
  • Identify and exploit vulnerabilities using ethical hacking techniques
  • Document findings in detailed technical and executive-level reports
Full document with email opt-in
Composition

What's inside the document.

01Role summary

One-paragraph plain-English explanation of the role's outcome and scope.

02Responsibilities

8 responsibilities phrased the way the work is actually done.

03Required qualifications

4 qualifications a candidate must have to perform on day 30.

04Preferred qualifications

3 qualifications that would make a candidate excellent in year two.

05Skills

6 skill chips you can copy directly into your ATS.

06Reporting line

Security Manager or CISO

What you receive

A complete document set.

  • Word document (.docx) — fully editable
  • PDF — signature-ready
  • Google Docs — one-click copy to your Drive
  • 12 months of updates to this document
  • Commercial-use licence for internal and client work
Responsibilities at a glance

The work, not the title.

  • Plan and execute authorized penetration tests on systems and networks
  • Identify and exploit vulnerabilities using ethical hacking techniques
  • Document findings in detailed technical and executive-level reports
  • Recommend remediation strategies for identified vulnerabilities
  • Stay current on emerging threats, exploits, and attack techniques
  • Collaborate with security and engineering teams on fixes
  • Conduct social engineering and physical security assessments as scoped
  • Maintain testing scope, rules of engagement, and legal compliance
Qualifications

Required — and what would make a candidate excellent.

Required
  • 3+ years of experience in penetration testing or security research
  • Strong knowledge of networking, operating systems, and web applications
  • Experience with common penetration testing tools and frameworks
  • Understanding of common vulnerability classes and attack techniques
Preferred
  • OSCP, CEH, or similar penetration testing certification
  • Scripting experience in Python, Bash, or PowerShell
  • Experience with cloud environment penetration testing
Skills
Ethical hackingVulnerability assessmentNetwork securityReport writingScriptingRisk analysis
How to use this template

Eight steps from download to publish.

  1. 01Open the Penetration Tester job description in Word or your one-click Google Docs copy.
  2. 02Replace placeholders for company name, reporting line, and location with your specifics.
  3. 03Tighten the summary to one paragraph that names the team's outcome, not just the role.
  4. 04Edit the responsibilities to match the actual scope of the seat — aim for 6 to 8 items, not 12.
  5. 05Separate required qualifications from preferred. Required is what a candidate must have to do the work on day 30; preferred is what would make them excellent in year two.
  6. 06Add salary range guidance using BLS, Payscale, or your own band data — do not copy generic figures.
  7. 07Have the hiring manager and one peer read it. Cut anything that wouldn't survive a candidate question.
  8. 08Publish to your ATS, intranet, and external careers page.
When to use this template

The right document at the right moment.

Use this Penetration Tester job description any time you are opening or reopening a seat at this level. The mid band sets the calibration — copy the document, tighten it to your specific scope, and circulate to the hiring panel before the first interview.

The reporting line (Security Manager or CISO) and skills list are starting points. Override either if your org structure or stack differs from the norm — the template is a draft, not a contract.

FAQ

Honest answers before you download.

Is a specific certification required for this role?
Certifications like OSCP or CEH are strong signals of skill but many employers weigh hands-on testing experience and a portfolio of findings just as heavily.
Does this role require on-site work?
Penetration testing is frequently remote-friendly, though some engagements involving physical security assessments may require on-site presence.
Legal note

This Penetration Tester job description is a professionally drafted starting point for your hiring process and is not legal advice. Hiring practice varies by jurisdiction (e.g. pay-transparency laws differ across US states and AU jurisdictions). Adapt this document for your specific location and have employment counsel review any clauses you add before publishing. Salary varies by region, employer type, and experience. Reference BLS or current industry surveys for ranges. Full disclaimer.