An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Wattlecorp Cybersecurity Labs LLP is seeking a hands-on Security Consultant/Penetration Tester to break and fix systems across client environments. You will conduct practical tests, write clear reports, and work directly with clients to translate findings into business risk.
The role emphasizes real testing, documentation, and collaboration with teams to improve security postures. Prior consulting experience and a proactive mindset are valued.
We’re looking for a Security Consultant/Penetration Tester who actually knows how to break things. Not someone who just lists tools on their resume, but someone who’s spent real time in the trenches doing penetration testing work. This is a hands-on role where you’ll be assessing security across diverse client environments.
– Security Assessments
You’ll conduct comprehensive security assessments across multiple domains:
About 60% of your time will be actual testing work. The other 40% involves documentation, reporting, client coordination, and the occasional VPN troubleshooting session with clients. We won’t pretend this is all exciting red team operations and zero-days. Most of it is solid, honest assessment work.
– Documentation & Reporting
This is where most pentesters struggle, so let’s be clear: you’ll write reports. Many reports. Clients don’t pay for screenshots of reverse shells, they pay for clear, actionable documentation that explains what’s broken and why it matters.
Your reports need to translate technical vulnerabilities into business risk. If your findings all look copy-pasted or say “XSS found, fix it” with no context, we’re all going to have a bad time.
– Client Engagement
– Experience
Minimum 2 years in penetration testing or security assessments. Real client engagements, real reports, real deadlines. Not just “I did HackTheBox for a year” (though that’s a good foundation). You should be comfortable independently handling standard assessments while knowing when to elevate complex scenarios.
Prior experience in a consulting or professional services environment is strongly preferred. You understand project-based delivery and client management.
– Technical Skills
You should be comfortable with manual penetration testing techniques across web applications, networks, APIs, mobile platforms, and cloud environments. Specifically:
– Scripting & Automation
Can you write a Python script that does something useful? Can you automate a boring task? Can you modify an exploit that’s almost-but-not-quite working?
You don’t need to be a software engineer, but you should be comfortable with Python and Bash scripting. If you can’t script your way out of a paper bag, this role will be painful.
– Certifications
Not strictly required, but they help. Ones we respect:
No cert? That’s fine if your practical skills back it up. But if you have neither certifications nor demonstrable experience, this isn’t an entry-level role.
– Frameworks & Standards
Working knowledge of security testing methodologies and compliance frameworks:
– Communication Skills
– The Right Mindset