Cyber Security -Senior Penetration Tester
We are looking for a Senior Penetration Tester to join our Cyber Security team and focus primarily on Application Security Penetration Testing. The role will involve hands-on security testing of web and mobile applications, identifying vulnerabilities, validating security risks, and providing actionable findings based on established testing methodologies and frameworks. The majority of the workload will be focused on Web Application Security Testing, with additional exposure to mobile and thick-client applications.
Key Responsibilities
- Perform penetration testing and vulnerability assessments at the application layer.
- Conduct Web Application Security Testing, which will make up the majority of the workload.
- Perform Mobile Application Security Testing, approximately 20% of the workload.
- Conduct Thick Client Testing; experience is preferred but training can be provided for a strong candidate.
- Identify, validate, exploit, and document security vulnerabilities.
- Execute penetration tests based on established testing methodologies, frameworks, and processes.
- Analyze findings and provide clear technical documentation and recommendations.
- Work with application and technical teams to communicate security findings and remediation requirements.
- Use industry-standard penetration testing tools and techniques to support security assessments.
Key Requirements
- Minimum 5+ years of hands-on penetration testing experience.
- Strong experience in Web Application Security Testing.
- Practical experience with Mobile Application Security Testing.
- Exposure to Thick Client Testing is an advantage; candidates can be trained if otherwise strong.
- Strong hands-on experience with:
- Burp Suite
- OSCP or CREST certification is mandatory.
- Strong understanding of application security vulnerabilities, exploitation techniques, and penetration testing methodologies.
- Ability to execute testing activities independently using established security frameworks and processes.
Work Scope
- Primary focus: Application Security Penetration Testing
- Web Application Testing: Majority of workload
- Mobile Application Testing: Approximately 20%
- Thick Client Testing: Limited; training can be provided
- Testing is performed at the application layer only.
- Testing methodologies, processes, and frameworks are already established.
- The successful candidate is expected to execute against existing frameworks rather than develop testing methodologies from scratch.
Ideal Candidate
The ideal candidate is a hands-on penetration tester with strong web application security expertise, solid practical knowledge of Burp Suite and Kali Linux, and a valid OSCP or CREST certification. Candidates who are comfortable executing structured penetration testing engagements and documenting technical findings will be a strong fit