About this role.
Cobalt is seeking an experienced, mid-level freelance pentester to join its curated Cobalt Core community on a part-time basis. The role performs manual security testing across web applications, APIs, internal and external networks, and iOS and Android applications. Responsibilities include validating vulnerabilities, assessing OWASP Top 10 risks, collaborating with pentest teams and clients, and producing detailed assessment reports. Candidates need at least four years of relevant experience, deep application-security knowledge, strong written communication, and a professional, collaborative approach.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
4/5Autonomy Level
5/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I begin by mapping the application’s attack surface, authentication flows, roles, endpoints, and data handling. I then prioritize high-risk areas such as access control, input handling, session management, and business logic, using automated tools only to support—not replace—manual validation. Each confirmed finding is reproduced, assessed for impact, and documented with clear remediation guidance.
I use the least invasive proof of concept needed to demonstrate exploitability and impact. I follow the rules of engagement, avoid accessing unnecessary data or disrupting services, and capture sufficient evidence for reproducibility. If a test could create material risk, I pause and obtain client or engagement-lead approval before proceeding.
I include a concise title, severity and rationale, affected assets, technical description, reproducible steps, sanitized evidence, business impact, and prioritized remediation guidance. I also state any assumptions or testing limitations so the client can accurately understand the scope and risk.
I first enumerate endpoints, methods, object identifiers, roles, and authorization boundaries. I then test horizontal and vertical privilege escalation by modifying object IDs, tenant identifiers, account references, request methods, and role-specific tokens. I validate findings with minimal-impact requests and clearly distinguish authentication failures from broken object- or function-level authorization.
I regularly review vulnerability disclosures, security research, OWASP guidance, vendor advisories, and practitioner communities. I reinforce that learning through lab environments, proof-of-concept reproduction, tool experimentation, and peer knowledge sharing. I also update my testing checklists as new attack patterns become relevant.
Who We Are
The Cobalt Core is a community of highly skilled security pentesters who are passionate about what they do and who are always striving to be at the top of their game. This curated community is made up by security professionals with many years of experience as well as talented pentesters who are eager to learn the trade and show their skills. They all have a strong drive to keep up to date on the latest vulnerabilities and exploits, and the tools and methodologies to find them.
A member of the Cobalt Core believes that sharing ideas and collaborating with peers is the best way to achieve good results.
If you believe you would be a good fit to join the Cobalt Core, and you are eager to contribute to the community and participate in the Pentests running on Cobalt please apply.
If you are currently residing in the USA, please apply here.
Who You Are
- 4+ years of Pentesting or similar experience (mid-level).
- Professional demeanor
- Respectful towards others
- Take pride in the work you produce
- Strong work ethic with attention to detail
- Desire to be an expert within your field
- Deep understanding of application security
- Ability to communicate effectively
- Collaborative spirit
What You’ll Do
- Perform manual penetration testing of web applications, APIs, internal and external networks, iOS and Android mobile applications
- Work as a member of a pentest team, collaborating and engaging directly with the client
- Document in detail the results of assessments, audits, tests, and verification activities
- Perform manual validation of vulnerabilities
- Perform mobile and web app pentesting for OWASP top 10 vulnerabilities.
- The following certifications are a plus:
- CREST, PenTest+, GPEN, CEH, OSCP, AWS, CISSP, eCPPT, eWAPT, OSCE, OSWE
- Please note that this is a freelance, part-time position.
Application Process: Applicants need only apply once and may not receive a response from our team. We review applications on a rolling basis and will reach out to a candidate should there be a mutual alignment. Repeated inquiries after applying and across social media is not favorable.
- Application – Becoming part of the Cobalt Core is a highly selective process, and only the best applicants will be invited to next steps in the on boarding process. Preference will be given to applicants who come referred by other Cobalt Core pentesters.
- Chat with a Cobalt representative – Get to know about Cobalt and how we work. We will also want to know about you, your experience, strengths and what drives you. If we all think it’s a great fit, we will explore how we can work together!
- Technical Skills Assessment to demonstrate your technical acumen and reporting.
- Getting setup on the Cobalt platform + Background Check & ID Verification – In this step we will make sure you are all set up for success, and we will also ask you to pass a Background Check & ID Verification.
- Start working on cool projects!
Please note that this is not an entry level position.
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.








