--- title: 'Associate, Compliance Security Penetration Tester at Coalfire' canonical: 'https://feeny.ai/job/associate-compliance-security-penetration-tester-coalfire-united-states-1wradjdtpp3y' type: 'job' last_seen: '2026-09-08' --- # Associate, Compliance Security Penetration Tester at Coalfire - **Company:** Coalfire - **Location:** United States - **Compensation:** $64k–$117k - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-08-19 - **Last confirmed live:** 2026-09-08 - **Apply:** https://jobs.lever.co/coalfire/59991dcb-2ca8-46d4-9b89-0d1b00e3e5eb ## Job description ## About Coalfire Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world. But that’s not who we are – that’s just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference. Working independently and collaboratively with a team to support the following work activities where skills apply such as: Internal and External Network Penetration Testing, Application Penetration Testing (Browser-based, API, Mobile), Cloud Solution Penetration Testing, Social Engineering, Wireless Assessments. Conduct security assessments on a wide variety of technologies and implementations. Simulate sophisticated cyberattacks for clients worldwide. ## What You'll Do - Advises clients on technical security or compliance activities - Manages priorities and tasks to achieve delivery utilization targets. - Operates with professionalism both internally and with clients. - Ensures quality products and services are delivered on time. - Continues to develop professional skills with relevant industry specific certifications. Maintains strong depth of knowledge in the practice area. - Collaborates with project managers, quality management, sales, and other delivery team members to drive customer satisfaction and meet project deliverables. - Develop processes, procedures, and methodologies to enhance testing processes and experience - Assist with report generation and quality assurance processes - Develop client relationships - Assist in the scoping of prospective engagements, leading engagements from initial stages through implementation and remediation - Manage project escalations of current testing being conducted - Mentor and develop less experienced staff - Contribute to the Penetration Testing Team overall success by managing your team to meet various business objectives and metrics ## What You'll Bring - Bachelor's degree (four-year college or university) or equivalent combination of education and work experience - 3+ years’ experience in information security with Web Application and Network penetration testing experience - Experience working with enterprise environments - Hands-on experience with scripting languages such as Python, Powershell, Shell, or Ruby - Experience with one or more IT security compliance frameworks, such as PCI, FISMA, HIPAA, FEDRAMP, or HITRUST - One to three (1-3) years of experience in an IT Security Audit and/or Compliance role - Experience interacting with management in a consultative manner - Strong IT understanding with respect to networks, servers, workstations, and applications - Excellent communication and presentation skills - Ability to travel up to 20% Bonus Points - Deep experience engaging clientele in consulting-related environments - Experience leading penetration team engagements - Reverse engineering malware, data obfuscators, or ciphers - An aptitude for technical writing, including assessment reports, presentations, and operating procedures - Strong understanding of security principles, policies, and industry best practices - Experience working with C and various compiler toolchains - Community contributions or participation including - CTF, Hack-the-box, or cyber-defense competitions - Speaking or presentations - Public security research ## Why You’ll Want to Join Us At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office. Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options. At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at HumanResourcesMB@coalfire.com. ## About Coalfire ## Company Overview - **One-liner**: Coalfire is a premier cybersecurity and compliance services firm that helps enterprises and tech companies navigate FedRAMP, cloud migration, AI risk, and penetration testing. - **Entity Type**: Private (owned by private equity firm Apax Partners; prior funding rounds include Series A, Series B, and venture rounds from Baird Capital) - **Headquarters**: Chicago, Illinois, United States - **Founded**: 2001 - **Founders**: Not publicly available ## Core Business - **Primary industry**: Cybersecurity & Compliance Services (professional services) - **Target customers**: B2B, enterprise, and government agencies in technology, healthcare, and finance sectors - **Mission or purpose**: “Making the world a safer place” by solving clients’ toughest cybersecurity challenges ## Products & Services - **Penetration Testing & Red Teaming**: Simulated attacks to identify vulnerabilities in networks, applications, and cloud environments. - **Compliance Assessments (FedRAMP, SOC 2, PCI-DSS, HIPAA/HITRUST)**: Third-party assessment organization (3PAO) services for government and commercial compliance frameworks. - **Cloud Security Consulting**: Google Cloud, AWS, and Azure security architecture, cloud migration, and cloud maturity assessments. - **Application Security & DevSecOps**: Secure software development lifecycle integration, mobile app security testing, and code review. - **Vulnerability Management**: Internal/external scans, ASV services, and continuous monitoring. - **AI Risk Advisory**: Assessing and managing risks associated with artificial intelligence deployments. - **Advisory & Strategy**: CISO program management, third-party risk management, and cyber breach response. ## Market Standing - **Valuation/Market Cap**: Not disclosed (private company) - **Key Metric**: Annual Revenue of **USD 200,000,000** (fiscal year ending July 31) | Total funding raised: **$9.35M** (primary rounds from 2011–2013, later private equity) - **Notable Investors/Partners**: Baird Capital (lead in Series A & B), Apax Partners (current owner) - **Growth Signals**: - 679 employees (+1.0% YoY); ~2.2% monthly LinkedIn follower growth - Acquired Veris Group (2016), Denim Group (2021), Neuralys (2021) - Recognized as a **Top Workplace** since 2018 - 990+ certifications held by employees, including 200+ cloud-related - Recipient of 2022 Secretary of Defense Employer Support Freedom Award and HIRE Vets Medallion Award ## Competitive Advantages - **Deep FedRAMP expertise** as a 3PAO advisory firm – a critical differentiator for government and regulated industries. - **Broad compliance framework coverage** (PCI-DSS, HIPAA, SOC 2, HITRUST, FISMA) allows cross-selling and one-stop-shop engagements. - **Acquired niche firms** (e.g., Denim Group for application security, Veris Group for FedRAMP) to build a comprehensive suite. - **Long-standing relationships** with major cloud providers (AWS, Google Cloud, Azure) and a strong alumni network feeding into top tech companies. ## Strategic Focus - **AI Risk & Cloud Migration**: Capitalizing on growing demand for AI governance and secure cloud adoption. - **Compliance Automation**: Developing tools and processes to streamline continuous compliance for clients. - **Expanding Hyperscaler Partnerships**: Recent job postings for a Director of Hyperscaler Strategy & Partnerships indicate a push to deepen ties with AWS, Google, and Azure. - **Talent Development**: Investing in employee certifications and tuition reimbursement to maintain a highly skilled workforce. ## Why Work Here - **Culture & Inclusion**: Coalfire emphasizes diversity, employee resource groups, team events (hikes, cookoffs, sporting events), and a “stronger together” ethos. - **Remote/Hybrid Policy**: Many roles are listed as **fully remote** (e.g., Detection and Response Engineer, Principal Cloud Engineer, Senior Google Cloud Security Consultant). The company also offers work-from-home opportunities. - **Benefits**: UnitedHealthcare coverage, flexible paid time off, tuition & certification reimbursement, fitness challenges, and an Employee Assistance Program. - **Growth & Recognition**: Voted a Top Workplace since 2018; strong support for veterans and active-duty service members. - **Engineering Culture**: Opportunity to work on cutting-edge cloud security, FedRAMP, and AI risk engagements with a team holding 990+ certifications. ## Sources 1. [linkedin.com](https://linkedin.com/company/coalfire) 2. [jobs.lever.co](https://jobs.lever.co/coalfire) 3. [coalfire.com](https://coalfire.com/about/careers) 4. [careers.coalfire.com](https://careers.coalfire.com/career-openings) ## Other roles at Coalfire - [Senior SIEM Engineer](https://feeny.ai/job/senior-siem-engineer-coalfire-united-states-wdzt07j4b2y7) — United States - [Principal Solutions Architect](https://feeny.ai/job/principal-solutions-architect-coalfire-united-states-wcytvxjvw91n) — United States - [Account Executive - Compliance Sales](https://feeny.ai/job/account-executive-compliance-sales-coalfire-united-states-90mcmcjx115g) — United States - [Account Executive - DivisionHex](https://feeny.ai/job/account-executive-divisionhex-coalfire-united-states-ssesj9vdve5f) — United States - [Account Executive - AI, Cloud and Compliance Advisory](https://feeny.ai/job/account-executive-ai-cloud-and-compliance-advisory-coalfire-united-states-0tcs1yt82q6w) — United States - [Principal Cloud Engineer](https://feeny.ai/job/principal-cloud-engineer-coalfire-united-states-tzhx2z18qqft) — United States - [Engagement Architect - Cloud Architecture (FedRAMP)](https://feeny.ai/job/engagement-architect-cloud-architecture-fedramp-coalfire-united-states-2zt8ph4srkeb) — United States - [Detection and Response Engineer (SPLUNK)](https://feeny.ai/job/detection-and-response-engineer-splunk-coalfire-united-states-qc0tw7a7ywmd) — United States - [Operational Technology Security Consultant](https://feeny.ai/job/operational-technology-security-consultant-coalfire-united-states-4h2yb05p2526) — United States - [Senior Google Cloud Security Consultant](https://feeny.ai/job/senior-google-cloud-security-consultant-coalfire-united-states-4gzmsx9babpw) — United States