The Penetration Tester is responsible foridentifying and assessing security vulnerabilities across applications,networks, and systems by performing controlled security assessments andsimulated attacks. The role involves using industry-standard tools andmethodologies to identify weaknesses, validate vulnerabilities, preparedetailed reports, and support remediation activities. The ideal candidateshould have a strong foundation in ethical hacking concepts, penetrationtesting techniques, and security best practices.
- Conductpenetration testing activities on web applications, networks, APIs, andsystems under defined testing scopes.
- Performvulnerability assessments and security reviews to identify potential securityrisks.
- Utilizemanual and automated penetration testing tools to identify and validatevulnerabilities.
- Performreconnaissance, vulnerability analysis, exploitation, andpost-exploitation activities as part of security assessments.
- Identifycommon vulnerabilities including OWASP Top 10, misconfigurations,authentication issues, and security weaknesses.
- Prepareclear and detailed penetration testing reports including findings, riskratings, evidence, and remediation recommendations.
- Communicatetechnical findings effectively with security teams, developers, andrelevant stakeholders.
- Assistdevelopment and infrastructure teams in validating security fixes andremediation efforts.
- Maintainknowledge of current vulnerabilities, attack techniques, and penetrationtesting methodologies.
- Assistin improving penetration testing processes, checklists, and documentation.
- Supportsecurity assessments, vulnerability management activities, andcompliance-related security testing.
- Maintainconfidentiality and follow ethical hacking guidelines during all testingactivities.
- Document testing procedures, findings, and lessonslearned
Requirements
Knowledge, Skills, Abilities (KSA’s) required tosuccessfully perform the job:
Knowledge:
- Good understanding of commonvulnerabilities, attack vectors, and exploitation techniques.
- Knowledge of OWASP Top 10vulnerabilities and web application security concepts.
- Understanding of network protocols,operating systems, and basic system architecture.
- Familiarity with penetration testingmethodologies such as PTES and OWASP Testing Guide.
- Hands-on knowledge of penetrationtesting tools such as:
- Burp Suite
- Nmap
- Nessus/OpenVAS
- Wireshark
- Basic understanding ofscripting/programming languages such as Python, Bash, or PowerShell.
- Understanding of security conceptsincluding authentication, authorization, encryption, and access controls.
- Awareness of security best practices andsystem hardening techniques.
Skills:
- Ability to perform penetration testingon web applications, networks, and APIs.
- Good technical skills in vulnerabilityidentification and exploitation.
- Ability to use penetration testing toolseffectively.
- Ability to create professionalvulnerability assessment and penetration testing reports.
- Strong analytical and problem-solvingskills.
- Ability to work independently andcollaborate with security and technical teams.
- Good attention to detail when analyzingsecurity weaknesses.
- Ability to research and learn newvulnerabilities and attack techniques.
Abilities:
- Ability to think from an attacker’sperspective to identify security weaknesses.
- Ability to analyze systems andapplications for potential vulnerabilities.
- Ability to reproduce and validatesecurity findings.
- Ability to explain technical issues toboth technical and non-technical stakeholders.
- Ability to manage multiple testing tasksand meet deadlines.
- Ability to maintain confidentiality andprofessional ethics.
- Ability to continuously improve technical knowledge in cybersecurity.
Education, Experience, Licensure, Certificationrequired for the position:
- Bachelor's degree in ComputerScience, Information Security, Cybersecurity, or a related field.
- 1–2 years of experience inpenetration testing, vulnerability assessment, or a related cybersecurityrole.
- Practical experience with webapplication, network, and API security testing.
- Relevant certifications are preferred, such as:CEH, eJPT, Security+, PNPT,OSCP (added advantage)
Competenciesrequired to successfully perform the job:
- 1.Web, network, and API penetration testing
- 2.Vulnerability Assessment & Reporting
- 4.Security Testing Methodologies
- 5.Basic Scripting (Python/Bash/PowerShell)