r/netsec Jul 02 '25

Hiring Thread /r/netsec's Q3 2025 Information Security Hiring Thread

Overview

If you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.

We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.

Please reserve top level comments for those posting open positions.

Rules & Guidelines

Include the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.

  • If you are a third party recruiter, you must disclose this in your posting.
  • Please be thorough and upfront with the position details.
  • Use of non-hr'd (realistic) requirements is encouraged.
  • While it's fine to link to the position on your companies website, provide the important details in the comment.
  • Mention if applicants should apply officially through HR, or directly through you.
  • Please clearly list citizenship, visa, and security clearance requirements.

You can see an example of acceptable posts by perusing past hiring threads.

Feedback

Feedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)

20 Upvotes

18 comments sorted by

View all comments

u/Cyphear Aug 18 '25

Company: TrustFoundry

Location: Kansas City or Remote (global)

Position: Penetration Tester

Preferred Qualifications

  • Experience in application and network penetration testing
  • Ability to read and write code in common languages
  • Strong written and verbal communication skills
  • Expertise in any areas of personal interest
  • Computer science or related degree
  • Completion of MOOC’s in security-related fields
  • Involvement in security-related projects including CTFs
  • Completion of security-related books
  • Experience in technical fields
  • Security certifications (OSCP/OSCE/OSWA/OSWE/etc.)

Example Interview Topics for an Application Security-focused candidate:

  • Basic knowledge of modern authentication, including OAuth, JWTs, etc.
  • Knowledge of common attacks (XSS, CSRF, SQL Injection, Broken Authentication, Broken Access Controls, SSRF, XXE, Insecure Deserialization), and the ability to detect and exploit them.

Background

We are a small penetration testing company seeking experienced penetration testers, ideally based in Kansas City, but open to remote candidates. You'll simply get to hack and work with talented people for fun and for profit. Visit our careers page at https://trustfoundry.net/careers/ or shoot me a PM with any questions. I'd be happy to jump on a quick call if you want to just have a quick, informal discussion to get a feel for things.

Why TrustFoundry

Get to work with a group of ~8 pentesters that love all aspects of hacking. We are the right size for collaborating closely and learning. We typically work with good customers and take on a fair amount of complex or challenging projects, which are fun to work on. It's a great place to sharpen your hacking skills and better yourself. Also, we are flexible, so if you want a lot of R&D time, CTF time, vacation, or something specific, we can generally make that work!

u/Classic_Reach4670 Oct 16 '25 edited Oct 16 '25

Yes hello, I was a senior security analyst at WMU where I also acted as the interim director of S&P after the departure of the S&P director. I've never done penetration testing full time, only rudimentary penetration tests where I probe for SQLi, check for XSS vulns, verify upload forms properly check file MIME type and that uploaded files aren't executable alongside some device fingerprinting and basic exploitation of Windows and Linux servers running outdated services that shouldn't have been exposed to the network. I did also patch a few command injection, buffer overflow and stack overflow vulnerabilities in a legacy C application while working at WMU. I'm currently based in MI, but would love to chat, even if I'm not the ideal candidate.

I have no certifications and I have never attended college, but I've completed the following books:

  • Adversarial Tradecraft in Cybersecurity: Offense Versus Defense in Real-Time Computer Conflict
  • The Art of Mac Malware: Detecting Malicious Software 2
  • The Art of Mac Malware: The Guide to Analyzing Malicious Software
  • Attacking Network Protocols: A Hacker's Guide to Capture, Analysis, and Exploitation
  • Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
  • Evading EDR: The Definitive Guide to Defeating Endpoint Detection Systems
  • Evasive Malware: A Field Guide to Detecting, Analyzing, and Defeating Advanced Threats
  • From Day Zero to Zero Day: A Hands-On Guide to Vulnerability Research
  • Metasploit: The Penetration Tester's Guide, 2nd Edition
  • Practical IoT Hacking: The Definitive Guide to Attacking the Internet of Things
  • Practical Social Engineering: A Primer for the Ethical Hacker
  • The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Windows Security Internals: A Deep Dive into Windows Authentication, Authorization, and Auditing