Avatar for Blackhatbrew
Blackhatbrew
Actively Hiring
Real world red team labs
  • Responds within three weeks
    Based on past data, Blackhatbrew usually responds to incoming applications within three weeks

Commission Only Sales Partner, Offensive Security Services

  • Remote (
    Everywhere
    )
  • |2 years of exp
  • |Full Time
Posted: 2 days ago• Recruiter recently active
Hires remotely in
Everywhere
Remote Work Policy

Remote only

Company Location
Visa Sponsorship

Not Available

Preferred Timezones
Pacific Time, Central Time, Eastern Time
RelocationAllowed
Skills
Penetration Testing
Cybersecurity
Offensive Security
Hiring contact
Muhammad Arafat
Founder
United States
image

About the job

This role pays commission only. No base salary, no retainer, no benefits, no expense budget. You get paid a percentage of every engagement you bring in, and you get paid after the client pays us. If you need predictable monthly income, this is not the role. If you already have a network in security or IT buying and you want to monetise it without leaving whatever else you do, keep reading.

Who we are

Black Hat Brew is a small offensive security crew. Three practitioners, no account managers, no handoffs. The people who scope an engagement are the people who run it, which is not how most firms this size work and is usually the thing that closes the deal.

What you would be selling

Four things, all scoped per client:

Scenario CTF Ranges. Full attack chain labs built on realistic corporate infrastructure, Active Directory, edge services, cloud identity. Mapped to MITRE ATT&CK. Sprints run three to seven days. Buyers are security teams who want to prove their people can handle a live attack chain instead of a checklist.

Red Team Simulations. Adversary emulation against a client's live environment with detection gaps documented. Two to four weeks. Buyers are SOC and detection engineering leads who need to know what their tooling misses.

Web Application Pentesting. Web apps, APIs, business logic flaws. One to three weeks.

Android Pentesting. APK teardown through runtime exploitation. One to two weeks.

Every engagement ships a report with findings, risk scores, remediation guidance and retest validation.

Who actually buys this

The people who sign are heads of security, CISOs at mid sized companies, security engineering leads, and founders of companies that just got told by a customer or an auditor that they need a pentest. Anything driven by SOC 2, ISO 27001, PCI or a client security questionnaire is a fast conversation, because the budget already exists and there is a deadline attached.

We are not chasing enterprises with eighteen month procurement cycles. We want companies that can decide in weeks.

What we want from you

You bring the clients. That is the whole job. You find them, you open the conversation, you qualify whether it is real, and you bring us in to scope it. We do not hand you a lead list, and we do not have an SDR feeding you appointments. If your plan is to work our pipeline, this will not work out.

You do not need to be technical enough to run a test. You do need to be technical enough to hold a credible first conversation with a security lead and not get dismissed in the first two minutes.

What we do

We take every technical call with you. We scope, price and write the proposal. We deliver the work, and we deliver it well, because your commission depends on the client paying and clients pay for work they are happy with. You get case material, sample reports and a walkthrough of each service so you can speak to it properly.

Commission

[COMMISSION]% of the contract value on every engagement you source, paid within [PAYMENT WINDOW] of the client's payment clearing. If a client pays in stages, you get paid in the same stages.

Recurring work counts. If a client you brought in comes back for a second engagement or a retest, you get paid on that too for [RENEWAL PERIOD].

Typical engagements run [DEAL SIZE RANGE], so a single closed deal is worth roughly [EXAMPLE COMMISSION] to you.

Refunds and chargebacks reverse the commission. That has never happened, but the term needs to be in the agreement.

The arrangement

Independent contractor. You invoice us, you handle your own taxes. Not exclusive, so you can sell other things as long as it is not directly competing. We will send a short agreement covering commission, payment timing, client attribution and confidentiality before you touch any client conversation.

Attribution is settled by who introduced the client first, in writing, on our shared record. We will not have an argument about this six months later.

How to apply

Do not send a generic pitch. Send:

  1. Two or three sentences on the security or IT buyers you already have access to and how you know them.
  2. One deal you closed on your own sourcing, roughly what it was worth, and how you found it.
  3. What commission percentage you would consider fair, and why.

Applications without those three things will not get a reply.

About the company

Blackhatbrew company logo

Blackhatbrew

Actively Hiring
Real world red team labs1-10 Employees
  • Responds within three weeks
    Based on past data, Blackhatbrew usually responds to incoming applications within three weeks
Learn more about Blackhatbrew image

Founders

Muhammad Arafat
Founder
United States
image
View the team image