Offensive Security Engineer — Fully Remote
Penetration Tester / Red Team (via CoTrain)Remote · $4,500–$10,000 / monthAbout this roleCoTrain is hiring on behalf of a team that needs an experienced offensive security specialist for a scoped, fully authorized engagement to test their CRM and related systems. The goal: demonstrate, under controlled conditions, the ability to access client data; identify real attack paths; and deliver a clear report with evidence and remediation steps so the team can close the gaps. CoTrain is a vetted marketplace that connects companies with elite, pre-screened experts, so you go straight to real work.All work is performed strictly within a written statement of work, rules of engagement, and legal authorization — limited sample data only, with no unauthorized exfiltration or disruption.What you'll ownPerform an authorized penetration test of the CRM and related systems within an agreed scopeIdentify and demonstrate real attack paths across credentials, permissions, APIs, and identityShow, under controlled conditions, where client data could be accessedDocument findings with clear evidence and reproducible stepsDeliver actionable, prioritized remediation guidance the team can implement to close the gapsWho you areProven experience in offensive security, penetration testing, or red teamingStrong grasp of identity, access control, API, and permission-based attack pathsExperienced testing SaaS/CRM or similar business-critical systemsRigorous about scope, authorization, and responsible disclosure — you operate strictly within rules of engagementExcellent reporting skills: you translate technical findings into clear, actionable remediation for both engineers and leadershipBonus pointsRelevant certifications (OSCP, OSCE, GPEN, GWAPT, or similar)Cloud security experience (AWS / GCP / Azure)Familiarity with common CRM platforms and their integration/API surfacesCompensation$4,500–$10,000/month, based on experience and scope. Remote, contract, fixed to a defined statement of work.Engagement termsThis is a controlled, legal, and fully authorized engagement governed by a signed SOW, rules of engagement, and NDA. Candidates must be comfortable working within strict, documented boundaries.How to applyApply through CoTrain, not by email — open the listing on CoTrain, sign in or create your expert profile if you're new, and submit with your relevant experience and a short note on why you're the one (including any redacted sample reports or certifications). You'll also take a short 8-minute interview as part of your application. From there you'll get vetted and matched through the platform, and we'll reach out to you on CoTrain.PS: We review applications daily — make sure you complete your 8-minute interview to be considered.