Senior Penetration Tester
Make an impact with NTT DATA. The Senior Penetration Tester is an advanced subject matter expert responsible for assessing and evaluating the security posture of the company’s information systems, networks, applications, and infrastructure. This role involves conducting rigorous and complex penetration testing and ethical hacking activities to identify vulnerabilities and potential weaknesses for exploitation, collaborating with cross‑functional teams, and providing strategic security recommendations to strengthen the organization’s overall cybersecurity defenses. The Senior Penetration Tester mentors junior members and is highly experienced in relevant exploits, tooling, and exploit writing, playing a pivotal role in the company’s continuous assessment program.
Key Responsibilities
- Plans, executes, and manages complex penetration testing engagements on various IT assets, including networks, applications, and databases.
- Conducts simulated cyber‑attacks, including social engineering, to identify vulnerabilities and assess the organization’s resilience to cyber threats.
- Performs penetration tests against internal and external facing systems.
- Analyzes and interprets penetration test results and provides detailed reports to relevant stakeholders.
- Provides input to improve the quality and effectiveness of tests in a highly scaled and global environment.
- Articulates complex technical risks through creation of reports and delivery of presentations to key stakeholders.
- Works with Security DevOps teams to test the orchestration and automation processes and platforms, feeding results into a testing program.
- Supports assessment risk and develops and/or recommends appropriate mitigation countermeasures based on empirical testing.
- Provides comprehensive technical expertise with web, application, and database vulnerability testing.
- Supports the development of the security automation framework and the implementation roadmap.
- Provides actionable security recommendations and mitigation strategies to address identified vulnerabilities.
- Ensures that penetration testing activities align with relevant industry standards, compliance regulations, and best practices, maintaining program integrity and independence within the organization.
- Contributes to any security awareness training and education programs to promote a culture of cybersecurity within the organization.
- Stays up to date with the latest cybersecurity threats, attack vectors, and defensive technologies to continuously improve testing methodologies.
- Mentors and guides less experienced members of the penetration testing team, sharing knowledge and best practices.
- Crafts payloads and executables for specific environments using obfuscation techniques to evade detection from advanced EDR systems.
Qualifications and Experience
- Ability to work independently and manage multiple projects within a remote environment.
- Strong ability to engage with various stakeholders, maintain a team‑based approach, and work toward shared goals.
- Creative thinking and passion for continual skill improvement and innovation.
- Proficiency in compromising systems and demonstrating lateral movement post‑compromise.
- In‑depth knowledge of common security assessment methodologies, such as OWASP, PTES, or NIST SP 800‑115.
- Strong understanding of various operating systems, network protocols, and application security.
- Advanced proficiency with penetration testing tools and frameworks, such as Metasploit, Burp Suite, Nmap, and Wireshark.
- Advanced knowledge of tools and technologies used to evaluate web applications, databases, and network infrastructure.
- Excellent analytical and problem‑solving skills to identify and exploit vulnerabilities effectively.
- Strong written and verbal communication skills to deliver clear and concise reports and recommendations to stakeholders.
- Ethical and professional conduct with a commitment to confidentiality and data privacy.
Academic Qualifications and Certifications
- Bachelor’s degree or equivalent in Information Technology, Computer Science, or related field.
- Security‑related certifications such as OSWE, OSEP, OSCP, OSCE, CRTP, GPEN, or CREST are desirable.
Additional Experience
- Advanced penetration testing experience and ethical hacking in a similar global environment.
- Experience with both commercial and open‑source security tools and scripting languages.
- Exposure to security testing scenarios such as Capture the Flag, Red Team, and Blue Team activities is desirable.
- Experience with testing platforms such as Hack the Box, Vulnhub, or PentesterLab is desirable.
Workplace Type
Hybrid Working.
Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment and do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category.