One Penetration Tester, assigned to your product and fully managed.

We assign a Penetration Tester to your team full time and run everything around them: a service delivery manager who answers for the work, training and coaching, the office and equipment, and HR and payroll. The price below is for a mid-level Penetration Tester; junior and senior levels are priced in your proposal, and how the monthly fee is built explains the arithmetic.

From price

One mid-level Penetration Tester, full time, everything below included. All 27 things included ››

  • Penetration tester From USD 3,600 per month
  • Service

    We manage and develop the team

    • A service delivery manager who runs the team and answers for delivery
    • A 1:1 with our Head of Delivery every two weeks
    • Weekly delivery scoring and monthly capacity reports
    • A Talent Success Manager for every specialist
  • HR

    We are the employer

    • Recruitment and technical assessment
    • Employment contracts
    • Salary and payroll
    • Tax and social security
  • Facilitation

    We provide the workplace

    • A desk in our own office in Chiang Mai or Bangkok
    • A Workplace Experience Manager on site
    • Team events through the year
    • IT support
  • Equipment

    We supply the tools

    • Laptop and hardware
    • Software licences
    • LinkedIn Learning access
    • Device security and management

What a Penetration Tester does on a dedicated cybersecurity team.

They test your staging and production systems within a written scope, report into your tracker and retest every finding once your own developers ship the fix.

Penetration Tester skills and technologies

  • Web application and API testing against the OWASP Top 10 and your product's own business logic.

  • Testing authentication, authorisation and tenant boundaries, where one user reaching another user's data does the most damage.

  • Infrastructure and cloud testing within an agreed scope, from exposed services to misconfigured storage.

  • Findings with steps to reproduce, a severity and a suggested fix, filed where your own developers work.

  • Retesting every fix, so a finding closes only once it is proven fixed.

Penetration Tester seniority levels.

Mid-level to senior. A tester who has seen many applications finds the business logic flaws that scanners miss. Seniority is one of the inputs into how the monthly fee is built.

When your team needs a Penetration Tester.

Assigned when a product changes too often for a yearly test to keep up, or when enterprise customers ask for recent test evidence. Pairs with a security engineer who fixes the root causes the tests reveal. Penetration testers join as part of a dedicated cybersecurity team at Azendo. It is a targeted addition for companies that hire a dedicated development team and sell to customers with strict security reviews.

What we look for in a dedicated Penetration Tester.

We look for testers who go beyond the scanner: people who understand how your product is meant to work and look for the ways it can be made to work differently. Clear written findings matter as much as finding the flaw.

A remote Penetration Tester's first three months on your team.

  1. Weeks 1 to 2Agreeing the scope and rules of engagement, and mapping your applications, APIs and exposed services.
  2. Weeks 3 to 6Running the first full test cycle and filing findings with steps to reproduce and suggested fixes.
  3. Months 2 to 3Retesting fixes, testing new releases as they ship and settling into a regular testing rhythm.
From USD 3,600
Per month for a mid-level penetration tester, fully managed
160 h
Typical monthly capacity for this role
Fixed
The same fee every month
4 to 6 weeks
From signing to our specialist starting
Monthly
Add or reduce hours at each cycle

Questions about adding a Penetration Tester to your team.

Is regular penetration testing safe for production?

Yes, when it is planned. Every test runs inside a scope you approve in writing: which systems, which techniques, which hours and who to call if something looks wrong. Disruptive tests run against staging, and anything that touches production is scheduled with your team.

Can we get a report to share with our customers?

Yes. Alongside the working findings in your tracker, the tester writes a summary of what was tested, what was found and what has been fixed and retested. Where a customer or auditor requires a test by an independent third party, our tester helps you prepare for that one too.

Tell us what your penetration tester would work on.

Loading the form…

We reply within one business day.