--- title: 'Penetration Tester at Bishop Fox' canonical: 'https://feeny.ai/job/penetration-tester-bishop-fox-mexico-b9emzzz80wa7' type: 'job' last_seen: '2026-09-08' --- # Penetration Tester at Bishop Fox - **Company:** Bishop Fox - **Location:** Mexico - **Work type:** remote - **Posted:** 2026-05-08 - **Last confirmed live:** 2026-09-08 - **Apply:** http://www.bishopfox.com/jobs?gh_jid=7905132 ## Job description At Bishop Fox, security isn't just a job - it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation. Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions - including 16 open-source tools and 50 security advisories published in the past five years - we're committed to making the digital world safer. Given our exceptional growth, we are expanding and hiring a Pen Tester to join us on this exciting journey. We’re looking for a talented, experienced professional hacker to help us secure some of the world’s most complex software and sophisticated technologies. You’ll be working alongside our US and internationally-based teams supporting clients across multiple industries. Who Are You and What You’ll Do You’re a cybersecurity consultant with a strong offensive security mindset and a passion for understanding how modern applications, cloud platforms, APIs, and emerging technologies operate at a deep technical level. You enjoy uncovering security weaknesses, thinking creatively about attack paths, and helping organizations solve complex security challenges through practical, risk-focused assessments. At Bishop Fox, you’ll work on a wide variety of security engagements including Cloud Security Assessments, Mobile Application Security Testing, Hybrid Application Assessments (HAA), and AI/LLM Security Assessments. You’ll evaluate modern applications and distributed systems across cloud-native, mobile, backend, and AI-enabled environments. Your responsibilities will include performing hands-on security testing, analyzing application behavior, reviewing source code, identifying realistic exploitation scenarios, and validating security controls across modern architectures. You’ll work closely with clients and internal teams to deliver high-quality technical assessments and actionable remediation guidance. As a consultant, you’ll contribute throughout the full engagement lifecycle from scoping and test planning to execution, reporting, and client presentations. Success in this role requires strong technical depth, structured testing methodologies, effective communication skills, and the ability to adapt quickly to new technologies and environments. ## Your Experience - 4+ years of experience in application security assessments, penetration testing, or offensive security engagements - Strong understanding of application security fundamentals, modern attack techniques, and common vulnerabilities affecting web applications, APIs, mobile applications, and cloud-native environments - Hands-on experience testing REST APIs, including authentication/authorization flaws, IDORs, injection vulnerabilities, session management issues, and business logic flaws - Strength with AWS services and cloud security concepts, including IAM, STS, S3, Lambda, API Gateway, CloudTrail, CloudWatch, and secure communication patterns such as SigV4 - Solid understanding of networking and web fundamentals, including HTTP/HTTPS, TCP/IP, DNS, API communication flows, cookies, headers, and related concepts - Experience reviewing source code for security issues in Java, C#, and Python applications - Knowledge of secure coding principles and common risks such as SSRF, insecure deserialization, injection vulnerabilities, sensitive data exposure, and insecure cloud integrations - Understanding of SDLC, CI/CD pipelines, and secure development practices - Experience using security assessment and code review tools such as Burp Suite, Semgrep, Git, AWS CLI, and API testing/debugging tools - Comfortable working across Linux, Windows, and macOS environments - Experience or strong interest in AI/LLM security, including prompt injection, RAG risks, insecure integrations, excessive permissions, and the OWASP Top 10 for LLM Applications - Strong written and verbal communication skills, with the ability to deliver clear, actionable findings and communicate technical risks to both technical and executive stakeholders - Experience following structured testing methodologies, documentation standards, and validation/retesting workflows - Strong collaboration and interpersonal skills when working with security, engineering, and client teams - Ability to manage multiple concurrent engagements while maintaining high-quality deliverables and attention to detail - Curious, adaptable, and professional mindset with a passion for continuous learning and emerging security trends ## Nice to Have - Exposure to hardware or embedded device security testing - Familiarity with cloud-native and serverless architectures - Consulting or client-facing experience - Relevant security certifications or hands-on research contributions ## Why Bishop Fox At Bishop Fox, we're driven by a simple mission: deliver exceptional quality to our clients, foster a vibrant and fulfilling environment for our team, and champion excellence within our industry. Our core values, which we live by every day, are: - Be Excellent to Each Other - Do the Right Thing - Do What You’ll Say You’ll Do - Get Better Together - Give a Sh*t At Bishop Fox, we're committed to providing benefits that support your well-being and professional growth. Here's a glimpse of what we offer: - Generous Time Off and Company-Wide Holidays - Team Events and International Travel Opportunities - Work From Home Support - Training Budget - Saving Fund - Food Coupons - Health and Wellbeing programs This position is not eligible for visa sponsorship. Applicants must be authorized to work in Mexico for the duration of employment without sponsorship. Bishop Fox is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.  All new hires must pass a background check as a condition of employment. Interested? Apply today! ## About Bishop Fox ## Company Overview - **One-liner**: Bishop Fox is the largest private professional services firm focused on offensive security testing, helping organizations proactively uncover and eliminate security exposures. - **Entity Type**: Private (Series B, $146M total funding) - **Headquarters**: Tempe, Arizona, United States - **Founded**: 2005 - **Founders**: Vincent Liu (CEO) and Francis Brown (Co-Founder and Board Member) ## Core Business - **Primary industry**: Cybersecurity / Offensive Security - **Target customers**: Enterprise (26% of the Fortune 100, 8 of the top 10 global tech companies, 5 of the top 5 global media companies, 7 of the top 10 manufacturers) - **Mission statement**: "To make the digital world safer for everyone." ## Products & Services - **Penetration Testing**: Simulates real-world attacks across applications, AI, cloud, and networks to identify vulnerabilities before they are exploited. - **Red Team & Readiness**: Full-scope adversarial simulations to stress-test defenses and incident response capabilities. - **Continuous Threat Exposure Management (CTEM)**: Ongoing discovery, testing, and threat monitoring to identify exposures on the attack surface with human validation. - **Bishop Fox Academy**: Internal training program combining educational content, real-world experience, and expert mentorship to develop security professionals. ## Market Standing - **Valuation/Market Cap**: Not disclosed (Private company) - **Key Metric**: $75M annual revenue (LinkedIn estimate); $146M total funding raised - **Notable Investors/Partners**: Carrick Capital Partners (lead, Series B), WestCap (lead, Series B), Forgepoint Capital (lead, Series A) - **Growth Signals**: 1,700+ customers protected; 26% of the Fortune 100 and 80% of the top 10 tech companies are clients; operates in 13 countries; NPS of 70 ("Excellent" in customer satisfaction) ## Competitive Advantages - **Scale and reputation**: Largest private professional services firm focused exclusively on offensive security; trusted by 26% of the Fortune 100 and 8 of the top 10 global tech companies. - **Deep expertise**: 20+ years of experience; 20+ open-source tools authored; 50+ security advisories published in the last 5 years. - **Remote-first culture**: Has operated as a remote-first company for years, allowing hiring of top talent globally across 13 countries. - **Bishop Fox Academy**: A dedicated internal training program with 1-on-1 mentorship, a video library, and training budgets — a strong differentiator for career growth in cybersecurity. ## Strategic Focus - **Continuous Threat Exposure Management (CTEM)**: Moving beyond point-in-time testing to continuous, real-time visibility and risk reduction. - **AI security**: Expanding offensive security services to cover emerging AI attack surfaces. - **Global expansion**: Operating in 13 countries with a distributed workforce, continuing to scale internationally. - **Talent development**: Investing heavily in Bishop Fox Academy and internal mentorship to grow the next generation of offensive security experts. ## Why Work Here - **Remote-first culture**: Bishop Fox has been remote-first for years, offering flexibility to work from anywhere in the U.S. and across 13 countries globally. [bishopfox.com](https://bishopfox.com/careers) - **Comprehensive benefits**: Full medical, dental, and vision; paid vacations and holidays; 401(k) with employer matching; phone and internet stipends; maternity and paternity leave. [bishopfox.com](https://bishopfox.com/careers) - **Bishop Fox Academy**: A standout training program with 1-on-1 mentorship, a video library created by penetration testers, training budgets, and both technical and non-technical career development support. [bishopfox.com](https://bishopfox.com/careers) - **Culture**: Values include "Do the Right Thing," "Be Excellent to Each Other," "Give a Shit," "Do What You Say You Will," and "Get Better Together." [bishopfox.com](https://bishopfox.com/careers) - **DEI commitment**: Active DEI program with strategic pillars focused on building a diverse organization, fostering an inclusive culture, and positively impacting the broader cybersecurity industry. [bishopfox.com](https://bishopfox.com/careers) - **Employee rating**: 3.7/5.0 on LinkedIn (111 reviews), with compensation rated 4.0/5.0 and work-life balance rated 3.8/5.0. [linkedin.com](https://www.linkedin.com/company/bishop-fox) - **Remote/hybrid policy**: Fully remote-first, with team members across the U.S., Mexico, Spain, the UK, Canada, France, and more. [bishopfox.com](https://bishopfox.com/careers) ## Sources 1. [bishopfox.com - Careers Page](https://bishopfox.com/careers) 2. [bishopfox.com - Homepage](https://bishopfox.com/) 3. [bishopfox.com - About Us](https://bishopfox.com/company) 4. [linkedin.com - Bishop Fox Company Profile](https://www.linkedin.com/company/bishop-fox) ## Other roles at Bishop Fox - [Account Executive - Pacific Northwest](https://feeny.ai/job/account-executive-pacific-northwest-bishop-fox-united-states-northwest-e6rnpdtsb0pn) — United States Northwest - [Infrastructure Engineer](https://feeny.ai/job/infrastructure-engineer-bishop-fox-united-states-k6awft3expha) — United States - [Solutions Engineer](https://feeny.ai/job/solutions-engineer-bishop-fox-united-states-p0m323vt5m4g) — United States - [Penetration Tester - Contract](https://feeny.ai/job/penetration-tester-contract-bishop-fox-united-states-11h771w1pdjp) — United States - [Penetration Tester](https://feeny.ai/job/penetration-tester-bishop-fox-united-states-jyb07awmtfax) — United States - [AI Software Engineer](https://feeny.ai/job/ai-software-engineer-bishop-fox-san-francisco-8ke6n1jk21p4) — San Francisco, CA - [Penetration Tester](https://feeny.ai/job/penetration-tester-spektrum-braine-l-alleud-hdas0dc75xyh) — Braine L’alleud, Belgium - [Penetration Tester](https://feeny.ai/job/penetration-tester-spektrum-braine-l-alleud-43k28xcjv58y) — Braine L’alleud, Belgium - [Penetration Tester](https://feeny.ai/job/penetration-tester-spektrum-the-hague-ngf19w8bqm7b) — The Hague, Netherlands - [Penetration Tester](https://feeny.ai/job/penetration-tester-spektrum-mons-ym2dyg6mxek8) — Mons, Belgium