Overview
Skills
Job Details
About the Role
We are seeking a highly skilled Penetration Tester to assess the security of applications, networks, and systems by simulating real-world cyberattacks. The ideal candidate will have strong technical expertise in offensive security, vulnerability assessment, and exploit development, with the ability to provide actionable remediation guidance.
Key Responsibilities
Conduct penetration testing on web applications, APIs, mobile apps, networks, and cloud environments.
Identify, exploit, and document security vulnerabilities.
Perform red team assessments and simulate advanced persistent threats (APTs).
Collaborate with development and infrastructure teams to recommend remediation strategies.
Prepare and deliver detailed reports (technical + executive summaries).
Stay updated with the latest security threats, tools, and attack vectors.
Assist in improving security controls and processes.
Mandatory Skills & Experience
Strong knowledge of offensive security methodologies (OWASP, PTES, NIST, MITRE ATT&CK).
Hands-on experience with penetration testing tools such as:
Burp Suite, Metasploit, Nmap, Wireshark, Nessus, Qualys, Kali Linux, Hydra, John the Ripper
Proficiency in at least one scripting/programming language (Python, Bash, PowerShell, Java, C/C++).
Deep understanding of web security, application security, network protocols, cloud security.
Strong grasp of exploitation techniques, privilege escalation, lateral movement.
Knowledge of Active Directory attacks, phishing simulations, social engineering.
Preferred/Good to Have
Experience in mobile app testing (Android/iOS).
Cloud security testing (AWS, Azure, Google Cloud Platform).
Container and Kubernetes security assessments.
Familiarity with SIEM/SOAR, IDS/IPS, and EDR solutions.
Certifications such as: OSCP, OSWE, GPEN, CEH, eCPPT, CRTP, CISSP.
Soft Skills
Strong analytical and problem-solving skills.
Ability to clearly communicate complex technical findings to both technical and non-technical stakeholders.
Detail-oriented with strong documentation and reporting skills.
Education
Bachelor s degree in Computer Science, Cybersecurity, Information Security, or related field (or equivalent experience).