[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Cobalt logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/7a1fbbfd-221.jpg)](https://jobicy.com/company/cobalt.md)Remote opportunity at[Cobalt](https://jobicy.com/company/cobalt.md)

# Cobalt Core Pentester

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/cobalt.md)Share16 Sep 2026Published31Listing views1Application actions16 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryCobalt is seeking an experienced, mid-level freelance pentester to join its curated Cobalt Core community on a part-time basis. The role performs manual security testing across web applications, APIs, internal and external networks, and iOS and Android applications. Responsibilities include validating vulnerabilities, assessing OWASP Top 10 risks, collaborating with pentest teams and clients, and producing detailed assessment reports. Candidates need at least four years of relevant experience, deep application-security knowledge, strong written communication, and a professional, collaborative approach.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

4/5IndependentCollaborative

AI insightThis is a highly selective technical security role requiring substantial hands-on penetration-testing experience across several attack surfaces. Success depends on independently finding, validating, and clearly reporting meaningful vulnerabilities while working effectively with clients and distributed assessment teams.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$125,000US market range$100k–$160k0$176k

AI insightNo compensation is disclosed, so these are estimated US annual full-time-equivalent market figures in USD for a mid-level application security/pentest professional with 4+ years of experience. Actual freelance, part-time earnings will vary materially based on hourly or project rates, workload availability, certifications, and testing specialization.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Penetration Testing](https://jobicy.com/jobs?search_keywords=Penetration%20Testing.md)[Application Security](https://jobicy.com/jobs?search_keywords=Application%20Security.md)[Web Application Security](https://jobicy.com/jobs?search_keywords=Web%20Application%20Security.md)[API Security Testing](https://jobicy.com/jobs?search_keywords=API%20Security%20Testing.md)[Network Penetration Testing](https://jobicy.com/jobs?search_keywords=Network%20Penetration%20Testing.md)[Mobile Application Security](https://jobicy.com/jobs?search_keywords=Mobile%20Application%20Security.md)[OWASP Top 10](https://jobicy.com/jobs?search_keywords=OWASP%20Top%2010.md)[Vulnerability Validation](https://jobicy.com/jobs?search_keywords=Vulnerability%20Validation.md)[Security Assessment Reporting](https://jobicy.com/jobs?search_keywords=Security%20Assessment%20Reporting.md)[Client Communication](https://jobicy.com/jobs?search_keywords=Client%20Communication.md)

Sample interview questionsDescribe your approach to manually testing a web application for OWASP Top 10 vulnerabilities.I begin by mapping the application’s attack surface, authentication flows, roles, endpoints, and data handling. I then prioritize high-risk areas such as access control, input handling, session management, and business logic, using automated tools only to support—not replace—manual validation. Each confirmed finding is reproduced, assessed for impact, and documented with clear remediation guidance.

How do you validate that a suspected vulnerability is a true positive without causing unnecessary risk to the client?

I use the least invasive proof of concept needed to demonstrate exploitability and impact. I follow the rules of engagement, avoid accessing unnecessary data or disrupting services, and capture sufficient evidence for reproducibility. If a test could create material risk, I pause and obtain client or engagement-lead approval before proceeding.

What information do you include in a high-quality penetration-test finding?

I include a concise title, severity and rationale, affected assets, technical description, reproducible steps, sanitized evidence, business impact, and prioritized remediation guidance. I also state any assumptions or testing limitations so the client can accurately understand the scope and risk.

How would you test an API for authorization flaws?

I first enumerate endpoints, methods, object identifiers, roles, and authorization boundaries. I then test horizontal and vertical privilege escalation by modifying object IDs, tenant identifiers, account references, request methods, and role-specific tokens. I validate findings with minimal-impact requests and clearly distinguish authentication failures from broken object- or function-level authorization.

How do you stay current with emerging vulnerabilities, exploitation techniques, and testing methodologies?

I regularly review vulnerability disclosures, security research, OWASP guidance, vendor advisories, and practitioner communities. I reinforce that learning through lab environments, proof-of-concept reproduction, tool experimentation, and peer knowledge sharing. I also update my testing checklists as new attack patterns become relevant.

Who We Are

The Cobalt Core is a community of highly skilled security pentesters who are passionate about what they do and who are always striving to be at the top of their game. This curated community is made up by security professionals with many years of experience as well as talented pentesters who are eager to learn the trade and show their skills. They all have a strong drive to keep up to date on the latest vulnerabilities and exploits, and the tools and methodologies to find them.

A member of the Cobalt Core believes that sharing ideas and collaborating with peers is the best way to achieve good results.

If you believe you would be a good fit to join the Cobalt Core, and you are eager to contribute to the community and participate in the Pentests running on Cobalt please apply.

If you are currently residing in the USA, please apply [here](https://boards.greenhouse.io/cobaltio/jobs/5688200002).

Who You Are

* 4+ years of Pentesting or similar experience (mid-level).
* Professional demeanor
* Respectful towards others
* Take pride in the work you produce
* Strong work ethic with attention to detail
* Desire to be an expert within your field
* Deep understanding of application security
* Ability to communicate effectively
* Collaborative spirit

What You’ll Do

* Perform manual penetration testing of web applications, APIs, internal and external networks, iOS and Android mobile applications
* Work as a member of a pentest team, collaborating and engaging directly with the client
* Document in detail the results of assessments, audits, tests, and verification activities
* Perform manual validation of vulnerabilities
* Perform mobile and web app pentesting for OWASP top 10 vulnerabilities.
* The following certifications are a plus:
CREST, PenTest+, GPEN, CEH, OSCP, AWS, CISSP, eCPPT, eWAPT, OSCE, OSWE

* Please note that this is a freelance, part-time position.

Application Process: Applicants need only apply once and may not receive a response from our team. We review applications on a rolling basis and will reach out to a candidate should there be a mutual alignment. Repeated inquiries after applying and across social media is not favorable.

* Application – Becoming part of the Cobalt Core is a highly selective process, and only the best applicants will be invited to next steps in the on boarding process. Preference will be given to applicants who come referred by other Cobalt Core pentesters.
* Chat with a Cobalt representative – Get to know about Cobalt and how we work. We will also want to know about you, your experience, strengths and what drives you. If we all think it’s a great fit, we will explore how we can work together!
* Technical Skills Assessment to demonstrate your technical acumen and reporting.
* Getting setup on the Cobalt platform + Background Check & ID Verification – In this step we will make sure you are all set up for success, and we will also ask you to pass a Background Check & ID Verification.
* Start working on cool projects!

Please note that this is not an entry level position.

Show more

[Apply now >](https://jobicy.com/jobs/153414-cobalt-core-pentester.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Cobalt logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/7a1fbbfd-221.jpg)
Cobalt  Sep 16

### [Cobalt Core Pentester – UK, Germany, Nordics](https://jobicy.com/jobs/153419-cobalt-core-pentester-uk-germany-nordics.md)

Who We Are The Cobalt Core is a community of highly skilled security pentesters who are passionate about what they do and who are always striving to be at the…

*
![Laminar Projects logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/5bd8df6b-221.png)
Laminar Projects  Sep 16

### [Vigilant IT Security Manager – Portugal/Poland](https://jobicy.com/jobs/153410-vigilant-it-security-manager-portugal-poland.md)

This is not an offshoring back-office job for an international company. You will be a key player in our globally distributed team. We’re searching for a Vigilant IT Security Manager…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 16

### [Public Facing Security Researcher](https://jobicy.com/jobs/153376-public-facing-security-researcher.md)

About the Company Born from groundbreaking research at Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart contracts, and decentralized applications…

*
![Socket logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/1314ce3c-221.png)
Socket  Sep 15

### [Vulnerability Research Engineer](https://jobicy.com/jobs/153339-vulnerability-research-engineer.md)

About Us Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our…

*
![Socket logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/1314ce3c-221.png)
Socket  Sep 15

### [Forward Deployed Engineer, Python](https://jobicy.com/jobs/153341-forward-deployed-engineer-python.md)

About Us Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our…

*
![LivePerson logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/49f9583c-221.jpeg)
LivePerson  Sep 15

### [SecOps Engineer I](https://jobicy.com/jobs/153310-secops-engineer-i.md)

LivePerson (NASDAQ:LPSN) is a Conversational AI company creating digital experiences that are Curiously Human. Everyperson is unique, and our technology makes it possible for companies, including leading brands like HSBC,…

*
![UpGuard logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/474a12c7-221.png)
UpGuard  Sep 14

### [Chief Information Security Officer](https://jobicy.com/jobs/153270-chief-information-security-officer-2.md)

Who are we? At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk…

*
![BetterHelp logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/0b48fde8-221.jpeg)
BetterHelp  Sep 13

### [Head of Security Engineering](https://jobicy.com/jobs/153174-head-of-security-engineering.md)

Who are we and why should you join us? BetterHelp is on a mission to remove the traditional barriers to therapy and make mental health care more accessible to everyone….

*
![Deloitte logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/370c2482dacb3fffbd4043cfca5674fe.png)
Deloitte  Sep 13

### [Manager, Cyber Compliance, Deloitte Global Technology](https://jobicy.com/jobs/150563-manager-cyber-compliance-deloitte-global-technology.md)

Job Type: Permanent Work Model: Remote Reference code: 134501 Primary Location: Toronto, ON All Available Locations: Toronto, ON   Our Purpose   At Deloitte, our Purpose is to make an impact that matters. We exist to inspire…

*
![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)
1Password  Sep 12

### [Manager, Security Incident Response](https://jobicy.com/jobs/153123-manager-security-incident-response.md)

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up…