About the role
Our client is seeking a motivated Junior Penetration Tester to support cybersecurity assessments and identify security weaknesses across web applications, networks, systems, and cloud environments. This role offers an excellent opportunity for individuals passionate about offensive security to gain hands-on experience in vulnerability assessments, penetration testing, and security validation activities while working alongside experienced cybersecurity professionals.
Key Responsibilities
- Perform vulnerability assessments and penetration testing on web applications, APIs, networks, and systems.
- Identify, analyze, and validate security vulnerabilities and misconfigurations.
- Conduct security testing using industry-standard tools and methodologies.
- Support internal and external penetration testing engagements.
- Prepare clear and concise technical reports documenting findings and remediation recommendations.
- Verify remediation efforts through re-testing and validation activities.
- Support security awareness initiatives, phishing simulations, and security assessments when required.
- Collaborate with infrastructure, application, and security teams to strengthen security controls.
- Maintain testing documentation, assessment evidence, and technical reports.
- Stay updated on emerging cybersecurity threats, vulnerabilities, and penetration testing techniques.
Requirements
- Basic understanding of networking concepts, including TCP/IP, DNS, HTTP/HTTPS, and common network protocols.
- Familiarity with Windows and Linux operating systems.
- Knowledge of common web application vulnerabilities, including OWASP Top 10.
- Understanding of vulnerability assessment and penetration testing methodologies.
- Exposure to security tools such as Burp Suite, Nmap, Nessus, Wireshark, or Metasploit.
- Basic scripting or programming skills in Python, PowerShell, Bash, JavaScript, or similar languages.
- Strong analytical, troubleshooting, and problem-solving skills.
- Good written and verbal communication skills.
- Ability to work independently and collaborate effectively within a team.
Preferred Qualifications
- Cybersecurity certifications such as eJPT, Security+, PNPT, CEH, or equivalent.
- Familiarity with the OWASP Testing Guide and MITRE ATT&CK Framework.
- Exposure to cloud security concepts in Microsoft Azure or AWS environments.
- Prior internship experience, academic cybersecurity projects, CTF participation, bug bounty activities, or related cybersecurity experience.