Velero is a cybersecurity and compliance consulting firm helping clients navigate complex regulatory requirements through expert-led assessments, advisory services, and practical security execution. Working across the computer and network security space, we partner with organizations to strengthen their security posture with clear, actionable guidance grounded in real-world risk.
In this role, you will help clients uncover vulnerabilities across a range of environments and contribute to security assessments that support both technical resilience and regulatory readiness. This is an opportunity for a penetration tester who enjoys tackling varied engagements, communicating findings clearly, and translating complex security issues into practical next steps for internal teams and clients.
Responsibilities
Conduct penetration tests on web applications, mobile applications, and APIs to identify vulnerabilities and potential exploits.
Perform network penetration testing, including internal and external network assessments, to ensure comprehensive coverage of security weaknesses.
Implement social engineering techniques such as phishing campaigns to simulate real-world attacks and identify human-related security risks.
Prepare detailed technical reports and provide actionable recommendations based on the results of penetration tests.
Collaborate with internal teams and external clients to discuss findings, mitigation strategies, and security best practices.
Ensure compliance with relevant security standards and regulations, including GDPR, PCI-DSS, SOC 2, and others.
Stay up to date on emerging threats, vulnerabilities, and security best practices.
Requirements
Required Qualifications:
Proven experience (3+ years) in penetration testing across web apps, mobile apps, APIs, and network environments.
Expertise in internal and external network penetration testing.
Knowledge of common security vulnerabilities and attack vectors, such as those listed in OWASP Top 10 and MITRE ATT&CK.
Familiarity with industry-standard tools like Burp Suite, Nmap, Metasploit, Wireshark, Nessus, and others.
Experience with cloud environments (AWS, Azure, Google Cloud) is a plus.
Strong understanding of GDPR, PCI-DSS, SOC 2, and other regulatory frameworks.
Excellent verbal and written communication skills, with the ability to present findings to technical and non-technical audiences.
Preferred Skills & Certifications:
Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), GIAC Penetration Tester (GPEN), or similar certifications.
Experience with mobile security frameworks and tools such as OWASP Mobile Security Testing Guide (MSTG).
Experience in API security testing, including OAuth and other common API security models.
Proficiency in one or more programming/scripting languages (Python, Bash, JavaScript, etc.).
Benefits
This position offers a flexible, remote contract opportunity for penetration testers looking to work on exciting security challenges in a nearshore environment. If you are a skilled security professional passionate about identifying vulnerabilities and strengthening security, we'd welcome your application.Why Join Us?
Competitive compensation of 120-160 USD per hour.
Flexibility of remote work with a nearshore focus.
Numbers & Facts
Location
Tampa, FL (Remote)
Skills
Amazon Web Services (AWS)unmatched
Application Programming Interface (API)unmatched
Bash Scriptingunmatched
Best Practicesunmatched
CEH - Certified Ethical Hackerunmatched
Campaignsunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Networksunmatched
Computer Securityunmatched
Consultingunmatched
Customer Support/Serviceunmatched
GPEN - GIAC Penetration Testerunmatched
Industry Standardsunmatched
Internet Applicationunmatched
Internet Securityunmatched
JavaScriptunmatched
Maintain Complianceunmatched
Metasploitunmatched
Microsoft Windows Azureunmatched
Mobile Applicationsunmatched
NMapunmatched
Nessusunmatched
Network Performance/Analysisunmatched
Network Securityunmatched
Network Testingunmatched
OAuthunmatched
PCI-DSSunmatched
Penetration Testingunmatched
Phishingunmatched
Presentation/Verbal Skillsunmatched
Python Programming/Scripting Languageunmatched
Regulationsunmatched
Regulatory Requirementsunmatched
Riskunmatched
Scripting (Scripting Languages)unmatched
Security Analysisunmatched
Security Complianceunmatched
Social Engineeringunmatched
Technical Presentationunmatched
Technical Supportunmatched
Testingunmatched
Wireshark (Ethereal)unmatched
Writing Skillsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.