Strengthen Cybersecurity Across the Information Technology Industry
Critical vulnerabilities demand sharp judgment, technical depth, and testing that earns customer trust. The Pen Test Engineer strengthens application security through rigorous assessments, validated findings, and practical remediation guidance. Expand your expertise in AI-assisted testing while protecting businesses against evolving threats. This opportunity offers a long-term global career with Emapta for top 1% talent seeking meaningful impact and professional growth.
Snapshot
- Employment Type: Full-time
- Work Setup: Permanent Work From Home
- Shift: Flexible Shift, Weekends Off
Benefits
- Day 1 HMO coverage with free dependent
- Competitive Salary Package
- Fixed weekends off
- Permanent Work From Home
- Salary Advance Program through our banking partner (Eligibility and approval subject to bank assessment. Available to account holders with minimum of 6 months company tenure.)
- Unlimited upskilling through Emapta Academy courses (Want to know more? Visit: https://emapta.com/training-calendar/)
- Free 24/7 access to our office gyms (Ortigas and Makati) with a free physical fitness trainer!
- Exclusive Emapta Lifestyle perks (hotel and restaurant discounts, and more!)
- Unlimited opportunities for employee referral incentives across the organization
- Standard government and Emapta benefits
- Total of 20 annual leaves to be used on your own discretion (including 5 credits convertible to cash)
- Fun engagement activities for employees
- Mentorship and exposure to global leaders and teams
- Career growth opportunities
- Diverse and supportive work environment
Qualifications
Education
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent work experience
Certification
- OSCP (Offensive Security Certified Professional) certification required
- Additional certifications such as OSWE, OSWA, GPEN, GWAPT, or CEH preferred
Experience
- At least 5 years of experience in offensive security, with demonstrable hands-on penetration testing of web applications and APIs, including REST and GraphQL
- Proven experience using AI tools for LLM-assisted reconnaissance, code review, exploit development, or reporting, with the ability to explain their benefits, limitations, and output validation methods
- Strong command of the OWASP Top 10, OWASP API Security Top 10, CWE, and modern authentication and authorization vulnerabilities
- Experience with automated and manual testing tools, such as Burp Suite Pro, Metasploit, Nmap, and ffuf
Technical Skills
- Proficiency in at least one scripting language, such as Python, Bash, or PowerShell, for custom tooling and exploit development
- Solid understanding of networking protocols, cryptography, session management, and authentication mechanisms
- Experience implementing or reviewing security controls in CI/CD pipelines (DevSecOps)
Soft Skills
- Excellent written and verbal communication skills, including the ability to brief engineers and executives
- Strong analytical and problem-solving skills, with sound judgment in assessing risk and exploitability
- Willingness to mentor junior testers and work in a collaborative, team-oriented environment
Preferred
- Experience in iOS and Android penetration testing, including static and dynamic analysis, traffic interception on modern platforms, certificate pinning bypass, insecure local storage assessment, and mobile API abuse testing
- Familiarity with OWASP MASVS/MASTG and tools such as Frida, Objection, MobSF, and Burp Suite for mobile testing
- Cloud security experience in AWS, Azure, or GCP, including configuration reviews and assessment of privilege escalation paths
- Experience in red team engagements, adversary simulation, or advanced persistent threat (APT) emulation
- Background in thick client, network, or internal infrastructure testing
- Participation in bug bounty programs or responsible disclosure processes
- Exposure to compliance frameworks such as SOC 2, ISO 27001, PCI DSS, HIPAA, or CMMC, including experience producing evidence that satisfies auditors
Responsibilities
Customer-Focused Penetration Testing
- Plan, execute, and manage customer penetration tests, primarily focusing on web applications and APIs.
- Conduct manual and automated testing to identify security flaws, misconfigurations, and exploitation paths.
- Scope engagements with customers and establish rules of engagement, timelines, and success criteria.
AI-Assisted Testing
- Apply AI and LLM-based tools to accelerate reconnaissance, payload generation, source code review, and report drafting, independently validating every finding before sharing it with customers.
- Test AI-enabled applications for prompt injection, insecure output handling, and data leakage in LLM-backed features.
- Help develop and refine internal AI-assisted testing workflows, prompts, and guardrails.
Quality Assurance and Mentorship
- Review and validate test reports, findings, and recommendations produced by other penetration testers.
- Provide constructive feedback and mentor junior and mid-level testers to maintain high-quality deliverables.
Remediation Guidance
- Provide customers with clear, actionable remediation strategies and security best practices.
- Collaborate with customer development and engineering teams on secure coding guidelines and improved security controls.
- Perform retesting and verify the effectiveness of implemented fixes.
Threat Modeling and Risk Analysis
- Conduct threat modeling exercises to proactively identify and assess security risks.
- Recommend countermeasures that measurably reduce customer exposure to threats.
Reporting and Documentation
- Create detailed technical reports and executive summaries tailored to different stakeholder audiences.
- Document testing methodologies, findings, and remediation actions to support transparency and compliance requirements.
Collaboration and Continuous Improvement
- Work with customer project managers, DevOps engineers, and IT security teams to align business goals with security objectives.
- Stay current on vulnerability research, security trends, and testing tools, incorporating relevant improvements into internal processes.
- Support incident response activities and post-incident reviews when requested.
About the Client
Our client helps businesses strengthen cybersecurity, achieve compliance, and earn stakeholder trust through continuous protection and expert guidance. Founded by experienced technology entrepreneurs, the company combines security expertise, automation, and personalized service to simplify complex compliance requirements. Its comprehensive approach supports audit readiness, identifies vulnerabilities, and strengthens security programs as threats evolve. By improving compliance visibility and reducing administrative effort, our client enables organizations to protect sensitive data, minimize business risk, and pursue growth with greater confidence and operational resilience.
Join the Top 1% Talent. A better career. A better life.
Welcome to Emapta Philippines: home to professionals who choose growth, balance, and impact. Recognized as one of HR Asia's Best Companies to Work For in Asia 2025 and winner of Inspiring Workplaces Australasia 2026, Emapta offers more than opportunities -- it provides a career environment where people thrive. Collaborate with global teams, build meaningful expertise, and grow in a culture that prioritizes both performance and well-being.