Our client, operating in cybersecurity solutions, is looking for a motivated Penetration tester.
Are you driven by offensive security and motivated to uncover critical vulnerabilities before malicious actors can exploit them? Do you excel at tackling complex security puzzles and helping organisations harden their defence posture?
In this role, you will perform technical security assessments targeting web applications, APIs, and mobile platforms to help clients spot and fix flaws proactively.
Responsibilities
- End-to-End Security Assessments: Plan and execute offensive security assessments targeting web applications, APIs, and mobile platforms following structured methodologies.
- Vulnerability Analysis & Validation: Identify, exploit, and confirm security flaws, assessing their potential business impact and likelihood of exploitation.
- Reporting & Advisory: Author comprehensive, professional reports tailored for technical and non-technical stakeholders, providing practical remediation advice.
- Client Engagement: Directly manage engagements from initial client scoping through final delivery, setting expectations and communicating progress.
- Research & Improvement: Stay updated on emerging attack vectors, refine internal testing toolkits, and share knowledge across the team.
Requirements
- Deep knowledge of common application vulnerabilities, attack frameworks, and offensive security techniques.
- Demonstrated ability to independently lead assessments from initial planning through final reporting.
- Strong verbal and written skills with a track record of producing clear technical reports for mixed audiences.
Benefits
Education and experience
- Minimum 1 year of hands-on application security testing (web, API, mobile) via professional work, bug bounties, CTFs (e.g., Hack The Box, TryHackMe), or security research.
- At least one practical certification (e.g., OSCP, OSWA, OSWE, HTB CWES/CWEE, or equivalent).