Job Title: Penetration Tester / Ethical Hacker
Job Summary
We are looking for a skilled Penetration Tester to identify, validate, and document security vulnerabilities across applications, networks, cloud environments, APIs, and enterprise infrastructure. The ideal candidate should have hands‑on experience conducting authorized security assessments and translating technical findings into actionable remediation recommendations.
Key Responsibilities
- Plan and execute authorized penetration tests and vulnerability assessments.
- Conduct testing of web applications, APIs, networks, cloud environments, and infrastructure.
- Identify and validate security vulnerabilities and potential attack paths.
- Perform manual and automated security testing.
- Conduct reconnaissance and security assessment activities within defined scope.
- Assess authentication, authorization, session management, input validation, and access controls.
- Test APIs for common security weaknesses and improper access controls.
- Perform network and infrastructure security testing.
- Assess cloud configurations and security controls across AWS, Azure, or GCP.
- Validate vulnerabilities discovered through automated scanning tools.
- Analyze findings and determine security impact and risk.
- Prepare detailed penetration‑testing reports with evidence and remediation recommendations.
- Communicate technical findings to security, engineering, and management teams.
- Perform remediation validation and follow‑up testing.
- Maintain testing methodologies, documentation, and security procedures.
- Stay current with emerging vulnerabilities, attack techniques, and security testing tools.
Required Skills
- 3+ years of experience in penetration testing, offensive security, or application security.
- Strong understanding of OWASP Top 10.
- Experience testing web applications, APIs, networks, and infrastructure.
- Knowledge of TCP/IP, DNS, HTTP/HTTPS, authentication, encryption, and networking.
- Experience with vulnerability scanners and penetration-testing tools.
- Strong Linux and Windows security knowledge.
- Scripting/programming experience with Python, Bash, PowerShell, or similar.
- Experience documenting vulnerabilities with clear technical evidence and remediation guidance.
- Understanding of CVSS, CWE, MITRE ATT&CK, and common vulnerability classifications.