L

Laika

End-to-end security compliance audit platform

Junior Penetration Tester

Full-Time
No salary listed
Junior
Remote in India+1 moreMore locations: North America
RemoteRemote within Latin America or India.

About the job

Requirements
  • One to two years of experience in penetration testing, vulnerability assessment, or a closely related offensive security role; internships, freelance work, and bug bounty experience count.
  • At least one of the following certifications: BSCP or OSCP.
  • Foundational understanding of web application security concepts, including the OWASP Top 10, common authentication and session management flaws, and injection vulnerabilities.
  • Willingness to use artificial intelligence tools in the workflow and a basic understanding of how to validate artificial intelligence-generated output rather than blindly trusting it.
  • Demonstrated passion for security through self-study, lab work, capture-the-flag participation, bug bounty programs, personal projects, or relevant coursework.
  • Any published security research, responsible disclosures, blog posts, or conference talks, regardless of size.
  • Fluency in English, with professional verbal and written communication, and the ability to convey complex technical topics to a range of stakeholders in a digestible manner.
Responsibilities
  • Perform web application, application programming interface, mobile, large language model, cloud, and network penetration tests using artificial intelligence tools and manual techniques, following established methodologies based on the OWASP Testing Guide and internal playbooks.
  • Use artificial intelligence-assisted tools for reconnaissance, payload generation, and initial triage while manually validating results and understanding the limitations of automated output.
  • Document findings clearly and accurately, including reproduction steps, evidence such as screenshots and request/response pairs, risk ratings, and remediation recommendations.
  • Help improve internal templates, skills, plugins, MCPs, checklists, and documentation as experience develops and improvement opportunities arise.
  • Assist senior testers with scoping calls and pre-engagement preparation when needed.

About the company

Laika provides a platform called Thororpass that helps businesses manage audits and achieve compliance across SOC 2, ISO 27001, HITRUST, and PCI DSS. Thororpass combines technology with expert auditors to support end-to-end audits, adapts to a company’s current compliance stage, and scales workflows as a business grows. It differentiates itself by offering an all-in-one solution for multiple frameworks with human oversight, reducing gaps and surprises compared to using separate tools or fragmented services. The goal is to make compliance worry-free, help organizations get compliant on the first attempt, and let teams focus on strategy and growth while security scales with the business.

Company Size

201-500

Company Stage

Series C

Total Funding

$98M

Headquarters

New York City, New York

Founded

2019

Get referred to Laika

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Thoropass launched Smart Sort AI on January 29, 2026, expanding evidence automation.
  • August 12, 2026 Inc. 5000 recognition signals continued revenue growth and market traction.
  • March 2026 AI-risk report positions Thoropass as a trusted voice on governance gaps.

What critics are saying

  • Vanta, Drata, and Secureframe pressure Thoropass with software-first models and broader ecosystems.
  • AI compliance tooling is commoditizing fast; January 2026 Smart Sort reduces switching friction.
  • If enterprises unbundle audits from software, Thoropass loses its core all-in-one wedge by 2027.

What makes Laika unique

  • Thoropass bundles audit software and in-house auditors, unlike Vanta or Drata.
  • Its July 2026 MCP Server targets AI-native audit workflows across customer agents.
  • Rebrand from Laika to Thoropass unified software, services, and assurance under one identity.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Early equity in a fast-growing company

Unlimited PTO

Remote work from home model

Stipend for home office equipment

Quarterly wellness and home wifi stipend

Paid courses and certifications

Growth & Insights and Company News

Headcount

6 month growth

↑ 4%

1 year growth

↑ 0%

2 year growth

↑ 4%
Laika
Mar 2nd, 2023
Laika Welcomes Dicken Chaplin as First CFO

After an exhaustive search, Laika is excited to welcome Dicken Chaplin as its first-ever CFO!

TechCrunch
Nov 8th, 2022
Laika laps up $50M for its automated security compliance platform

GDPR, HIPAA, SOC 2... compliance is the order of the day for organizations wanting to work together and to keep customers' trust.

PR Newswire
Aug 30th, 2022
Glean Ai Completes Soc 2® Type 1 Attestation With Laika

Glean AI is committed to the industry's highest standards for managing customer data and has partnered with Laika to build credibility with customers. NEW YORK, Aug. 30, 2022 /PRNewswire/ -- Glean AI , a SaaS company that helps businesses save money through deep insights and automation, announced today they have completed the SOC 2® Type 1 attestation

PR Newswire
Jul 27th, 2022
Hubsync Completes Soc 2® Type 1 Certification With Laika

Achieving SOC 2 compliance highlights HubSync's commitment to the top CPA firms and tax professionals' highest standards for managing customer data. BOSTON, July 27, 2022 /PRNewswire/ -- HubSync , the industry's first fully digital, end-to-end productivity platform for top CPA firms and tax professionals, announced today they have completed the SOC 2® Type 1 examination and are officially SOC 2 compliant

PR Newswire
Jun 28th, 2022
Reprise Completes Soc 2® Type 2 Audit, Enhancing Commitment To Security, Privacy, And Confidentiality

BOSTON, June 28, 2022 /PRNewswire/ -- Reprise , the only demo creation platform go-to-market teams use to create both live and guided demos, announced the successful completion of its System Organization Control (SOC) 2 Type 2 audit. The American Institute of Certified Public Accounts (AICPA) developed the SOC 2® Type 2 auditing standards, requiring all security practices and processes meet or exceed AICPA Trust Service Criteria. Reprise