Penetration Tester

CyberOne

Manila

Remote

PHP 900,000 - 1,200,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

CyberOne is a pure-play Microsoft security partner delivering security services and advisory across Defender XDR, Sentinel, Entra and more. We are seeking a Penetration Tester to perform extensive engagements against enterprise networks, with a strong focus on Active Directory security and exploitation techniques.

The role requires hands-on testing using tools like BloodHound, Mimikatz, Metasploit, and Nmap, plus excellent reporting and collaboration with clients to remediate findings.

Qualifications

  • Proven experience conducting penetration tests across enterprise networks and infrastructure.
  • Strong knowledge of Windows environments and Active Directory security.
  • Experience identifying and exploiting Active Directory vulnerabilities and attack paths.
  • Excellent understanding of network protocols and architecture, Windows Server administration, Kerberos and NTLM authentication, privilege escalation techniques, and lateral movement methodologies.

Responsibilities

  • Conduct comprehensive penetration testing engagements against enterprise infrastructure, networks, systems, and applications.
  • Perform manual and automated security assessments to identify vulnerabilities, weaknesses, and potential attack vectors.
  • Assess and exploit Active Directory environments, identifying security risks including misconfigurations and privilege escalation paths.
  • Execute network and system exploitation activities to validate security weaknesses and assess impact.
  • Evaluate the effectiveness of security controls, hardening measures, and defensive configurations within AD environments.
  • Simulate real-world attack scenarios to assess organizational resilience against threats.
  • Develop detailed technical reports outlining attack paths, findings, business impact, and remediation.
  • Present findings to technical and non-technical stakeholders; support remediation with best-practice guidance.

Skills

Penetration testing
Windows security
Active Directory security
Privilege escalation
Lateral movement
Security assessments
Attack vectors
Reporting

Education

OSCP
CREST CRT/CCT INF
GPEN
Microsoft security certs

Tools

BloodHound
Mimikatz
CrackMapExec
Impacket
Nmap
Burp Suite
Metasploit
Responder

Job description

Job Description

“I am hugely excited about my future and the future of CyberOne. I have enjoyed my time here immensely and have learnt a huge amount in a short space of time, year-for-year I've learnt more here than I have at Microsoft and PwC.” - CyberOne Consultant

About CyberOne

CyberOne is a pure-play Microsoft security partner dedicated to helping enterprises realise the full value of the Microsoft Security portfolio—across Defender XDR, Sentinel, Entra, Purview, Intune, Copilot for Security and more. We combine deep technical expertise with outcome-driven services that accelerate secure cloud adoption, modernise threat protection and simplify compliance.

Job Title: Penetration Tester
Location

Remote

Employment Type

Full-time

Key Responsibilities
  • Conduct comprehensive penetration testing engagements against enterprise infrastructure, networks, systems, and applications.
  • Perform manual and automated security assessments to identify vulnerabilities, weaknesses, and potential attack vectors.
  • Assess and exploit Active Directory environments, identifying security risks including:
    • Misconfigurations
    • Privilege escalation paths
    • Lateral movement opportunities
    • Credential theft vulnerabilities
    • Excessive permissions and insecure delegation
  • Execute network and system exploitation activities to validate security weaknesses and assess their impact.
  • Evaluate the effectiveness of security controls, hardening measures, and defensive configurations within Active Directory environments.
  • Simulate real-world attack scenarios to assess organizational resilience against cyber threats.
  • Develop detailed technical reports outlining attack paths, findings, business impact, proof-of-concept evidence, and remediation recommendations.
  • Present technical findings to both technical and non-technical stakeholders.
  • Work closely with internal teams and clients to support remediation efforts and provide security best-practice guidance.
  • Stay up to date with emerging threats, attack techniques, exploitation methodologies, and security technologies.
Required Skills & Experience
  • Proven experience conducting penetration tests across enterprise networks and infrastructure.
  • Strong knowledge of Windows environments and Active Directory security.
  • Experience identifying and exploiting Active Directory vulnerabilities and attack paths.
  • Excellent understanding of:
    • Network protocols and architecture
    • Windows Server administration
    • Authentication mechanisms (Kerberos, NTLM)
    • Privilege escalation techniques
    • Lateral movement methodologies
  • Hands-on experience with penetration testing and red team tools such as:
    • BloodHound
    • Mimikatz
    • CrackMapExec
    • Impacket
    • Nmap
    • Burp Suite
    • Metasploit
    • Responder
  • Familiarity with vulnerability assessment and security testing methodologies including OWASP, NIST, and PTES.
  • Strong technical documentation and report-writing skills.
  • Excellent analytical, troubleshooting, and problem-solving abilities.
Preferred Qualifications
  • Offensive Security Certified Professional (OSCP)
  • CRTO (Certified Red Team Operator)
  • CREST Registered Penetration Tester (CRT) or CREST Certified Infrastructure Tester (CCT INF)
  • GIAC Penetration Tester (GPEN)
  • Relevant Microsoft security certifications
  • Experience delivering internal or external client-facing security assessments
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester - Hybrid - BGC - up to 100K
Penetration Tester - Hybrid - BGC - up to 100K

weSource Management Consultancy Firm • Taguig

Hybrid
Penetration Tester - Up to 100K - Hybrid BGC - Midshift
Penetration Tester - Up to 100K - Hybrid BGC - Midshift

weSource Management Consultancy Firm • Metro Manila

Hybrid
PHP 80,000 - 100,000
Remote Penetration Tester for Enterprise AD & Security
Remote Penetration Tester for Enterprise AD & Security

CyberOne • Manila

Remote
PHP 900,000 - 1,200,000
Cybersecurity – Senior Penetration Tester
Cybersecurity – Senior Penetration Tester

Radii Global • Philippines

On-site
PHP 1,200,000 - 1,800,000
Penetration Tester (SMB)
Penetration Tester (SMB)

BreachLock Inc. • Hinoba-an

On-site
PHP 800,000 - 1,200,000
Private Health Insurance
Cyber Security -Senior Penetration Tester
Cyber Security -Senior Penetration Tester

Radii Global • Quezon City

On-site
PHP 1,200,000 - 1,800,000
Penetration Tester (Reverse Engineering and Embedded Code experience)
Penetration Tester (Reverse Engineering and Embedded Code experience)

Dencom Consultancy and Manpower Services • Mandaluyong

On-site
Penetration Tester (Reverse Engineering and Embedded Code Experience)
Penetration Tester (Reverse Engineering and Embedded Code Experience)

Dencom Consultancy and Manpower Services • Manila

On-site
Commission
Performance Bonus
Paid Holidays
+2
Penetration Tester (Reverse Engineering and Embedded Code Experience)
Penetration Tester (Reverse Engineering and Embedded Code Experience)

Dencom Consultancy & Manpower Services • Manila

On-site
Penetration Testing Analyst
Penetration Testing Analyst

Sun Life • Taguig

On-site
PHP 600,000 - 900,000