Penetration Tester

SQUAD - Cabinet de conseils et d’expertises

España

On-site

PHP 3,762,000 - 5,643,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SQUAD - Cabinet de conseils et d’expertises is seeking a Junior Pentester to join a hands-on pentest practice focused on web, mobile, and API applications. You will work with senior testers on long-running client missions, conduct hands-on assessments, and document findings clearly to grow into more autonomous engagements.

Responsibilities include testing web apps, APIs, and mobile apps per OWASP guidelines, performing vulnerability discovery, and contributing to internal docs while supporting

Qualifications

  • 3 years of cybersecurity experience with at least 1 year in app pentesting.
  • Solid knowledge of web vulnerabilities (injection, authN/authZ, SSRF, IDOR).
  • Experience with Burp Suite, ZAP, and recon/exploitation tooling.
  • Basic scripting (Python or Bash) to support testing.
  • Preferred: eJPT, eWPT, OSCP or equivalent hands-on credentials.

Responsibilities

  • Pen-test web apps, APIs, and mobile apps following OWASP methods.
  • Perform manual and tool-assisted vulnerability discovery.
  • Reproduce, validate, and document vulnerabilities with evidence and risk framing.
  • Write pentest reports and executive summaries in English.
  • Support remediation discussions with development teams.
  • Contribute to internal methodology and checklists.
  • Work on long-duration client missions with consistent quality.

Skills

Cybersecurity experience
Application pentesting
Burp Suite
OWASP ZAP
Python
Bash
English proficiency
Independent working

Tools

Burp Suite
OWASP ZAP

Job description

Since 2011, SQUAD Group has been a key player in the cybersecurity landscape. We partner with leading organizations to protect their information systems through a comprehensive 360° offering of consulting, integration, expertise, and managed services

Our mission: Securing Together!

We believe in a collaborative approach to cybersecurity, where experts and clients work hand-in-hand to anticipate threats and protect critical infrastructure.

As part of our growing team, we're seeking a Junior Pentester

Your Role

You are a hands-on, curious security tester joining a pentest practice focused on web, mobile, and API applications. Working alongside senior pentesters on long-running client missions, you'll conduct hands-on assessments, document findings clearly, and grow into more autonomous engagements over time.

Your Responsibilities
  • Conduct penetration tests on web applications, APIs, and mobile apps, following OWASP methodologies (OWASP Top 10, ASVS, MASVS).
  • Perform manual and tool-assisted vulnerability discovery (Burp Suite, OWASP ZAP, Nmap, and similar tooling).
  • Reproduce, validate, and document vulnerabilities with clear technical evidence and business-risk framing.
  • Write clear, well-structured pentest reports and executive summaries in English for international clients.
  • Support remediation discussions with development teams, explaining findings and validating fixes.
  • Contribute to internal methodology, checklists, and knowledge-sharing within the pentest team.
  • Work on long-duration client missions, maintaining consistent quality and communication throughout the engagement.
What You Bring
  • 3 years of experience in Cybersecurity, including at least 1 year dedicated to application penetration testing.
  • Solid understanding of web application vulnerabilities (injection, authN/authZ flaws, SSRF, IDOR, etc.) and common exploitation techniques.
  • Working knowledge of Burp Suite, ZAP, and standard recon/exploitation tooling.
  • Basic scripting ability (Python or Bash) to support testing and automation.
  • Fluent professional English, spoken and written — required for client-facing missions and report writing.
  • Comfortable working independently on long missions while staying aligned with senior pentesters and client stakeholders.
Preferred Certifications:

eJPT, eWPT, OSCP (in progress or recently obtained), or equivalent hands-on offensive security credentials.

Why Join Squad?

Personalized Growth: We help you build a training and certification plan aligned with your professional goals through our SquadExeperience

  • Expertise Development: Participate in internal events like our MixYourTalent webinars and monthly CTF sessions.
  • Visibility: Attend major industry conferences and contribute to our #TheExpert technical blog
  • Culture: Enjoy a dynamic and close-knit environment with after-work events and team gatherings that foster great camaraderie.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior Penetration Tester - Web/API/Mobile Security
Junior Penetration Tester - Web/API/Mobile Security

SQUAD - Cabinet de conseils et d’expertises • España

On-site
PHP 3,762,000 - 5,643,000
Penetration Tester (SMB)
Penetration Tester (SMB)

BreachLock Inc. • Hinoba-an

On-site
PHP 800,000 - 1,200,000
Private Health Insurance
Cyber Security -Senior Penetration Tester
Cyber Security -Senior Penetration Tester

Radii Global • Quezon City

On-site
PHP 1,200,000 - 1,800,000
Cybersecurity – Senior Penetration Tester
Cybersecurity – Senior Penetration Tester

Radii Global • Philippines

On-site
PHP 1,200,000 - 1,800,000
Penetration Tester - Up to 100K - Hybrid BGC - Midshift
Penetration Tester - Up to 100K - Hybrid BGC - Midshift

weSource Management Consultancy Firm • Metro Manila

Hybrid
PHP 80,000 - 100,000
Penetration Tester - Hybrid - BGC - up to 100K
Penetration Tester - Hybrid - BGC - up to 100K

weSource Management Consultancy Firm • Taguig

Hybrid
Penetration Tester
Penetration Tester

Our Clients • Manila

On-site
PHP 1,200,000 - 1,800,000
Penetration Testing Analyst
Penetration Testing Analyst

Sun Life • Philippines

On-site
PHP 600,000 - 900,000
Security Penetration Tester
Security Penetration Tester

Gratitude Philippines • Manila

Hybrid
PHP 1,200,000 - 2,400,000
Competitive salary package
Performance bonus
Day 1 HMO and Life Insurance
+2
Penetration Tester (Reverse Engineering and Embedded Code experience)
Penetration Tester (Reverse Engineering and Embedded Code experience)

Dencom Consultancy and Manpower Services • Mandaluyong

On-site