Congrats! You've completed step #1

FYSA: There are 4 steps total in submitting an application to work for us as an Experienced Offensive Security Tester:

  1. The step you just completed
  2. The next step documented below
  3. Sending a crafted HTTP POST (details provided later)
  4. Submitting a ~20-question screener with a mix of Yes/No answers, simple one-liner answers, and a single 2-min audio recording/one-way interview

Note: This has been taking junior and experienced pentesters about 10 minutes total for all steps leading to the application, and another ~10 minutes to complete the application itself. If it is taking you significantly longer, you might not have the experience we're looking for.

Next steps:

  1. Visit https://penconsultants.com/tanium
  2. Create a dictionary using the words on that page. If you can't do that from the Linux command line (wget/curl, awk, sed, sort, uniq, etc.) without using a tool (ex. cewl), there is no need to continue this application process as you will not be able to complete later challenges.
  3. Enumerate subdomains under the penconsultants.com domain using that list and that list only. Note the wildcarded domain.
  4. Dump the DNS TXT records for each FQDN discovered and follow the instructions to Step #3.