All remote jobs
Open role
Remote opportunity atCobalt

Cobalt Core Pentester

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
27Listing views
1Application actions
16 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

Cobalt is seeking an experienced, mid-level freelance pentester to join its curated Cobalt Core community on a part-time basis. The role performs manual security testing across web applications, APIs, internal and external networks, and iOS and Android applications. Responsibilities include validating vulnerabilities, assessing OWASP Top 10 risks, collaborating with pentest teams and clients, and producing detailed assessment reports. Candidates need at least four years of relevant experience, deep application-security knowledge, strong written communication, and a professional, collaborative approach.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

4/5
IndependentCollaborative
AI insightThis is a highly selective technical security role requiring substantial hands-on penetration-testing experience across several attack surfaces. Success depends on independently finding, validating, and clearly reporting meaningful vulnerabilities while working effectively with clients and distributed assessment teams.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$125,000
US market range$100k–$160k
AI insightNo compensation is disclosed, so these are estimated US annual full-time-equivalent market figures in USD for a mid-level application security/pentest professional with 4+ years of experience. Actual freelance, part-time earnings will vary materially based on hourly or project rates, workload availability, certifications, and testing specialization.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
Describe your approach to manually testing a web application for OWASP Top 10 vulnerabilities.

I begin by mapping the application’s attack surface, authentication flows, roles, endpoints, and data handling. I then prioritize high-risk areas such as access control, input handling, session management, and business logic, using automated tools only to support—not replace—manual validation. Each confirmed finding is reproduced, assessed for impact, and documented with clear remediation guidance.

How do you validate that a suspected vulnerability is a true positive without causing unnecessary risk to the client?

I use the least invasive proof of concept needed to demonstrate exploitability and impact. I follow the rules of engagement, avoid accessing unnecessary data or disrupting services, and capture sufficient evidence for reproducibility. If a test could create material risk, I pause and obtain client or engagement-lead approval before proceeding.

What information do you include in a high-quality penetration-test finding?

I include a concise title, severity and rationale, affected assets, technical description, reproducible steps, sanitized evidence, business impact, and prioritized remediation guidance. I also state any assumptions or testing limitations so the client can accurately understand the scope and risk.

How would you test an API for authorization flaws?

I first enumerate endpoints, methods, object identifiers, roles, and authorization boundaries. I then test horizontal and vertical privilege escalation by modifying object IDs, tenant identifiers, account references, request methods, and role-specific tokens. I validate findings with minimal-impact requests and clearly distinguish authentication failures from broken object- or function-level authorization.

How do you stay current with emerging vulnerabilities, exploitation techniques, and testing methodologies?

I regularly review vulnerability disclosures, security research, OWASP guidance, vendor advisories, and practitioner communities. I reinforce that learning through lab environments, proof-of-concept reproduction, tool experimentation, and peer knowledge sharing. I also update my testing checklists as new attack patterns become relevant.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

Who We Are

The Cobalt Core is a community of highly skilled security pentesters who are passionate about what they do and who are always striving to be at the top of their game. This curated community is made up by security professionals with many years of experience as well as talented pentesters who are eager to learn the trade and show their skills. They all have a strong drive to keep up to date on the latest vulnerabilities and exploits, and the tools and methodologies to find them.

A member of the Cobalt Core believes that sharing ideas and collaborating with peers is the best way to achieve good results.

If you believe you would be a good fit to join the Cobalt Core, and you are eager to contribute to the community and participate in the Pentests running on Cobalt please apply.

If you are currently residing in the USA, please apply here.

Who You Are

  • 4+ years of Pentesting or similar experience (mid-level).
  • Professional demeanor
  • Respectful towards others
  • Take pride in the work you produce
  • Strong work ethic with attention to detail
  • Desire to be an expert within your field
  • Deep understanding of application security
  • Ability to communicate effectively
  • Collaborative spirit

What You’ll Do

  • Perform manual penetration testing of web applications, APIs, internal and external networks, iOS and Android mobile applications
  • Work as a member of a pentest team, collaborating and engaging directly with the client
  • Document in detail the results of assessments, audits, tests, and verification activities
  • Perform manual validation of vulnerabilities
  • Perform mobile and web app pentesting for OWASP top 10 vulnerabilities.
  • The following certifications are a plus:
    • CREST, PenTest+, GPEN, CEH, OSCP, AWS, CISSP, eCPPT, eWAPT, OSCE, OSWE
  • Please note that this is a freelance, part-time position.

Application Process: Applicants need only apply once and may not receive a response from our team. We review applications on a rolling basis and will reach out to a candidate should there be a mutual alignment. Repeated inquiries after applying and across social media is not favorable.

  1. Application – Becoming part of the Cobalt Core is a highly selective process, and only the best applicants will be invited to next steps in the on boarding process. Preference will be given to applicants who come referred by other Cobalt Core pentesters.
  2. Chat with a Cobalt representative – Get to know about Cobalt and how we work. We will also want to know about you, your experience, strengths and what drives you. If we all think it’s a great fit, we will explore how we can work together!
  3. Technical Skills Assessment to demonstrate your technical acumen and reporting.
  4. Getting setup on the Cobalt platform + Background Check & ID Verification – In this step we will make sure you are all set up for success, and we will also ask you to pass a Background Check & ID Verification.
  5. Start working on cool projects!

Please note that this is not an entry level position.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu