All remote jobs
Open role
Remote opportunity atCobalt

Cobalt Core Pentester – UK, Germany, Nordics

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
20Listing views
0Application actions
16 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

Cobalt is seeking an experienced, freelance part-time penetration tester to join its curated Cobalt Core community. The role performs manual security testing across web applications, APIs, internal and external networks, and iOS and Android applications. Responsibilities include validating vulnerabilities, assessing OWASP Top 10 risks, documenting findings thoroughly, collaborating with pentest teams, and communicating directly with clients. Candidates need at least four years of relevant pentesting experience, strong application-security knowledge, professional communication skills, and a collaborative, detail-oriented approach.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

4/5
IndependentCollaborative
AI insightThis is a highly selective mid-level security role requiring deep manual testing capability across several attack surfaces and accurate vulnerability validation. Pentesters must independently identify, reproduce, prioritize, and clearly report technically complex findings while working with clients and distributed teams.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$130,000
US market range$110k–$155k
AI insightNo actual salary, hourly rate, or compensation range is disclosed in the posting. The figures shown are estimated US-market annualized full-time-equivalent base-pay benchmarks in USD for a mid-level application security penetration tester with 4+ years of experience; freelance part-time engagement earnings may vary materially based on hours, geography, project volume, and contract rates.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
Describe your methodology for a manual web application penetration test.

I begin by defining scope and rules of engagement, then map the attack surface through reconnaissance, application exploration, and endpoint enumeration. I test authentication, authorization, session handling, input validation, business logic, and common OWASP risks, validating exploitability and impact before documenting reproducible evidence and remediation guidance.

How do you distinguish a theoretical vulnerability from a reportable finding?

I verify that the issue is reproducible within the agreed scope and assess whether it has meaningful security impact. I collect concise evidence, explain prerequisites and attack paths, avoid overstating impact, and provide a severity rationale and practical remediation recommendation.

What would you test when assessing an API?

I review API documentation and observed traffic, enumerate endpoints and methods, and test authentication, authorization, object-level access controls, input handling, rate limiting, token management, error handling, and excessive data exposure. I pay particular attention to BOLA/IDOR issues and business-logic flaws that automated tools may miss.

How do you communicate a high-severity finding to a client who is not deeply technical?

I lead with the business impact and a plain-language explanation of what an attacker could accomplish, then summarize likelihood, affected assets, and urgency. I provide a short demonstration or evidence where appropriate, followed by prioritized remediation steps and technical details for the engineering team.

How do you keep your pentesting skills current?

I regularly study vulnerability research, vendor advisories, OWASP guidance, exploit write-ups, and changes in cloud and application frameworks. I also maintain hands-on practice through labs, tooling experiments, peer knowledge sharing, and retrospectives from completed assessments.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

Who We Are

The Cobalt Core is a community of highly skilled security pentesters who are passionate about what they do and who are always striving to be at the top of their game. This curated community is made up by security professionals with many years of experience as well as talented pentesters who are eager to learn the trade and show their skills. They all have a strong drive to keep up to date on the latest vulnerabilities and exploits, and the tools and methodologies to find them.

A member of the Cobalt Core believes that sharing ideas and collaborating with peers is the best way to achieve good results.

If you believe you would be a good fit to join the Cobalt Core, and you are eager to contribute to the community and participate in the Pentests running on Cobalt please apply.

Please note, this application is for candidates residing in the UK, Germany, and Nordic countires.

If you are currently residing in the USA, please apply here.

If you currently reside outside the USA, UK, Germany, or the Nordics please apply here.

Who You Are

  • 4+ years of Pentesting or similar experience (mid-level).
  • Professional demeanor
  • Respectful towards others
  • Take pride in the work you produce
  • Strong work ethic with attention to detail
  • Desire to be an expert within your field
  • Deep understanding of application security
  • Ability to communicate effectively
  • Collaborative spirit

What You’ll Do

  • Perform manual penetration testing of web applications, APIs, internal and external networks, iOS and Android mobile applications
  • Work as a member of a pentest team, collaborating and engaging directly with the client
  • Document in detail the results of assessments, audits, tests, and verification activities
  • Perform manual validation of vulnerabilities
  • Perform mobile and web app pentesting for OWASP top 10 vulnerabilities.
  • The following certifications are a plus:
    • CREST, PenTest+, GPEN, CEH, OSCP, AWS, CISSP, eCPPT, eWAPT, OSCE, OSWE
  • Please note that this is a freelance, part-time position.

Application Process: Applicants need only apply once and may not receive a response from our team. We review applications on a rolling basis and will reach out to a candidate should there be a mutual alignment. Repeated inquiries after applying and across social media is not favorable.

  1. Application – Becoming part of the Cobalt Core is a highly selective process, and only the best applicants will be invited to next steps in the on boarding process. Preference will be given to applicants who come referred by other Cobalt Core pentesters.
  2. Chat with a Cobalt representative – Get to know about Cobalt and how we work. We will also want to know about you, your experience, strengths and what drives you. If we all think it’s a great fit, we will explore how we can work together!
  3. Technical Skills Assessment to demonstrate your technical acumen and reporting.
  4. Getting setup on the Cobalt platform + Background Check & ID Verification – In this step we will make sure you are all set up for success, and we will also ask you to pass a Background Check & ID Verification.
  5. Start working on cool projects!

Please note that this is not an entry level position.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu