Rapid7
Penetration Tester, Vector Command, Vulnerability Management & External Network
Be an Early Applicant
As a penetration tester, you'll conduct external network testing, manage vulnerability scans, and collaborate with a Red Team to enhance security for clients.
Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client's perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defense strategies.
As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defense strategies
About the Team
Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise.
After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities-it tests the customer's entire security posture and defense-in-depth strategy.
In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments.
About the Role
Your primary responsibility is to deliver Rapid7's Vector Command Continuous Red Teaming service. In this role, you will conduct external network penetration testing and manage vulnerability scan dashboards, exploiting vulnerabilities, identifying the impact of exposures, and then searching for vulnerabilities that automated tooling may miss. The focus is on continuous perimeter testing to identify attack vectors that could lead to a breach. Specifically, your focus will be to:
The skills and qualities you'll bring include:
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-PB1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,000+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defense strategies
About the Team
Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise.
After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities-it tests the customer's entire security posture and defense-in-depth strategy.
In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments.
About the Role
Your primary responsibility is to deliver Rapid7's Vector Command Continuous Red Teaming service. In this role, you will conduct external network penetration testing and manage vulnerability scan dashboards, exploiting vulnerabilities, identifying the impact of exposures, and then searching for vulnerabilities that automated tooling may miss. The focus is on continuous perimeter testing to identify attack vectors that could lead to a breach. Specifically, your focus will be to:
- Manage automated vulnerability scan data across numerous customers, identifying and validating vulnerabilities which can be used to gain initial access into an organization.
- Perform external network penetration testing activities across a large attack surface, searching for vulnerabilities and misconfigurations that automation often misses.
- Upon successful exploitation, work with your Vector Command team to evaluate the impact through post-compromise breach simulation.
- Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction.
- Develop and maintain positive relationships with clients and understand their business and needs
- Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices
The skills and qualities you'll bring include:
- 3+ years in an active technical security role.
- Knowledge of Cybersecurity standards and industry best practices
- Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet-facing attack surfaces
- The ability to translate technical concepts and convey them to non-security personnel
- Technical competencies, including previous technical consulting experience
- High quality report writing and peer reviewing
- Certifications such as GPEN, CPTS, OSCP, CREST
- Experience with Red & Purple Teams
- Excellent communication skills both with internal and external stakeholders
- Collaborative mindset, contributing to knowledge sharing and cross training
- Demonstrate a commitment to the "end-to-end" testing process, from the initial pre-engagement planning to providing accountable support during the final remediation phase.
- Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-PB1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,000+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
Top Skills
Cpts
Crest
Cybersecurity Standards
Gpen
Oscp
Similar Jobs at Rapid7
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
As a Vector Command Specialist, you'll improve clients' security posture through offensive security strategies, conducting external attack surface analysis, managing customer inquiries, and preparing Red Team deliverables while collaborating with technical teams.
Top Skills:
PowershellPython
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
As a Penetration Tester, you'll design social engineering campaigns, emulate adversarial tactics, and improve clients' security postures through offensive operations and collaboration with Red Team.
Top Skills:
AnsiblePHPPythonRubyTerraform
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
The Principal AI Engineer will design and implement AI models and systems, mentor team members, and ensure AI solutions deliver real customer value.
Top Skills:
Aws BedrockCrewaiHuggingfaceKerasNumpyPandasPythonPyTorchSagemakerScikit-LearnTensorFlowTransformers
What you need to know about the Bristol Tech Scene
Along with Gloucester, Swindon and Bath, Bristol is part of the "Silicon Gorge" tech hub, a region in the U.K. renowned for its high-tech and research-driven industries, with a particular emphasis on sustainability and reducing environmental impact. As the European Green Capital, Bristol is home to 25,000 cleantech companies, including Baker Hughes and unicorn Ovo Energy. The city has committed to achieving net-zero emissions within the next decade.

