Cyber Security Consultant – Penetration Tester

Redherd.Io

Johannesburg

Hybrid

ZAR 650,000 - 900,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Redherd.Io is seeking a Cybersecurity Consultant focusing on penetration testing to join our client ecosystem in Johannesburg. You will conduct web and mobile application testing, as well as internal infrastructure assessments, delivering practical remediation guidance to customers.

This hands-on role requires clear communication of technical findings to both technical and non-technical stakeholders, the ability to manage multiple engagements simultaneously, and a strong commitment to

Qualifications

  • A relevant IT, computer science, cybersecurity or related diploma or degree.
  • At least three years of practical penetration-testing experience.
  • Strong hands-on web application penetration-testing experience.
  • Practical mobile application penetration-testing experience.
  • Experience conducting internal infrastructure or network security assessments.
  • Knowledge of common web and mobile application vulnerabilities.
  • Ability to conduct manual testing rather than relying only on automated scanning tools.
  • Ability to validate findings and explain realistic attack paths.
  • Strong written English and penetration-testing report-writing skills.
  • Ability to communicate findings and remediation guidance to customers.
  • Understanding of penetration-testing methodologies and rules of engagement.
  • Strong technical investigation and problem-solving abilities.
  • Ability to work independently and as part of a technical team.
  • Ability to manage multiple assessments and delivery deadlines.
  • Reliable transport for occasional office, customer or engagement requirements.

Responsibilities

  • Conduct web application penetration tests.
  • Conduct mobile application penetration tests across relevant platforms.
  • Perform internal infrastructure and network penetration tests.
  • Identify, validate and safely demonstrate exploitable security vulnerabilities.
  • Distinguish genuine security findings from false positives.
  • Assess the potential technical and business impact of identified vulnerabilities.
  • Maintain accurate evidence and testing notes throughout each engagement.
  • Produce clear, detailed and technically accurate penetration-testing reports.
  • Explain security findings to technical and non-technical stakeholders.
  • Provide practical, risk-based remediation recommendations.
  • Conduct findings presentations and engagement close-out discussions.
  • Support vulnerability retesting and confirm whether remediation has been effective.
  • Rapidly develop knowledge across new technologies, platforms and security challenges.
  • Investigate and evaluate cybersecurity tools and technologies.
  • Recommend security solutions appropriate to specific technical and business requirements.
  • Collaborate with technical consultants and other internal teams.
  • Support relevant pre-sales discussions by providing technical insight and expertise.
  • Share offensive-security knowledge, methodologies and best practices.
  • Manage multiple testing engagements and competing priorities.
  • Provide guidance to less-experienced team members where required.
  • Conduct all testing within agreed scopes, rules of engagement and ethical boundaries.

Skills

Penetration testing
Web application testing
Mobile application testing
Report writing
Client communication

Education

Diploma or degree in IT / Cybersecurity

Job description

Cybersecurity Consultant: Penetration Testing

Location: Johannesburg
Employment type: Permanent
Work model: Primarily remote, with occasional on-site and customer-facing requirements

About Redherd

Redherd is a specialist technical cybersecurity recruitment company supporting organisations across South Africa and international markets. We connect experienced security professionals with technically challenging opportunities across security operations, incident response, offensive security, engineering and security leadership.

About the Client

Our client is an established South African cybersecurity and managed services provider supporting complex enterprise and regulated environments. Its services include penetration testing, security operations, incident response, threat hunting, security engineering and network services.

The company operates within a highly ethical, security-focused environment and places strong emphasis on professional development, technical training and recognised industry certifications. It is ISO 27001 certified and offers employees opportunities to develop their careers across different cybersecurity disciplines.

Role Overview

The Cybersecurity Consultant will conduct practical penetration tests and security assessments across web applications, mobile applications and internal infrastructure environments.

This is a hands-on consulting position requiring strong technical testing abilities, mature professional judgement and the ability to communicate security findings clearly to customers.

Web and mobile application penetration testing are the primary focus areas. The role also includes internal infrastructure testing, technical reporting, remediation guidance, customer presentations and evaluating security tools and technologies.

A software development background is not required, although application security knowledge, scripting ability and an understanding of how modern applications are built will be valuable.

Key Responsibilities
  • Conduct web application penetration tests.
  • Conduct mobile application penetration tests across relevant platforms.
  • Perform internal infrastructure and network penetration tests.
  • Identify, validate and safely demonstrate exploitable security vulnerabilities.
  • Distinguish genuine security findings from false positives.
  • Assess the potential technical and business impact of identified vulnerabilities.
  • Maintain accurate evidence and testing notes throughout each engagement.
  • Produce clear, detailed and technically accurate penetration-testing reports.
  • Explain security findings to technical and non-technical stakeholders.
  • Provide practical, risk-based remediation recommendations.
  • Conduct findings presentations and engagement close-out discussions.
  • Support vulnerability retesting and confirm whether remediation has been effective.
  • Rapidly develop knowledge across new technologies, platforms and security challenges.
  • Investigate and evaluate cybersecurity tools and technologies.
  • Recommend security solutions appropriate to specific technical and business requirements.
  • Collaborate with technical consultants and other internal teams.
  • Support relevant pre-sales discussions by providing technical insight and expertise.
  • Share offensive-security knowledge, methodologies and best practices.
  • Manage multiple testing engagements and competing priorities.
  • Provide guidance to less-experienced team members where required.
  • Conduct all testing within agreed scopes, rules of engagement and ethical boundaries.
Minimum Requirements
  • A relevant IT, computer science, cybersecurity or related diploma or degree.
  • At least three years of practical penetration-testing experience.
  • Strong hands-on web application penetration-testing experience.
  • Practical mobile application penetration-testing experience.
  • Experience conducting internal infrastructure or network security assessments.
  • Knowledge of common web and mobile application vulnerabilities.
  • Ability to conduct manual testing rather than relying only on automated scanning tools.
  • Ability to validate findings and explain realistic attack paths.
  • Strong written English and penetration-testing report-writing skills.
  • Ability to communicate findings and remediation guidance to customers.
  • Understanding of penetration-testing methodologies and rules of engagement.
  • Strong technical investigation and problem-solving abilities.
  • Ability to work independently and as part of a technical team.
  • Ability to manage multiple assessments and delivery deadlines.
  • Reliable transport for occasional office, customer or engagement requirements.
Advantageous Experience
  • Application security assessments.
  • API penetration testing.
  • External infrastructure penetration testing.
  • Wireless security assessments.
  • Cloud security assessments.
  • Active Directory security testing.
  • Source-code review.
  • Secure development practices.
  • Scripting or programming for testing and automation.
  • Custom tooling or exploit development.
  • Participation in responsible disclosure or bug-bounty programmes.
  • Public security research, technical blogs or conference presentations.
  • Relevant penetration-testing training or certifications.
  • Experience using practical training platforms such as Hack The Box, TryHackMe or Proving Grounds.

Certifications are advantageous but are not an absolute requirement where a candidate can demonstrate strong practical penetration-testing experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Cybersecurity Penetration Tester & Consultant
Remote Cybersecurity Penetration Tester & Consultant

Redherd.io • Johannesburg

On-site
ZAR 350,000 - 520,000
Senior Penetration Tester & Security Consultant (Remote)
Senior Penetration Tester & Security Consultant (Remote)

Redherd.Io • Johannesburg

Hybrid
ZAR 650,000 - 900,000
Penetration Tester
Penetration Tester

Deka Minas (Pty) Ltd • Johannesburg

On-site
ZAR 600,000 - 900,000
Cyber Security Engineer (Pen Tester)
Cyber Security Engineer (Pen Tester)

Reverside • Johannesburg

On-site
ZAR 900,000 - 1,200,000
Penetration Tester
Penetration Tester

Placements24 • Gqeberha

On-site
ZAR 500,000 - 900,000
Medical aid
Retirement benefits
Paid time off
+1
Cyber Security Engineer (Pen Tester)
Cyber Security Engineer (Pen Tester)

reversidesoftwaresolutionspt • Johannesburg

On-site
ZAR 900,000 - 1,200,000
Cyber Security Engineer (Pen Tester) at reversidesoftwaresolutionspt
Cyber Security Engineer (Pen Tester) at reversidesoftwaresolutionspt

Reverside • Johannesburg

On-site
ZAR 700,000 - 950,000
Senior Specialist – Cyber Security Assurance
Senior Specialist – Cyber Security Assurance

Reverside • Johannesburg

On-site
ZAR 900,000 - 1,300,000
Senior Specialist – Cyber Security Assurance
Senior Specialist – Cyber Security Assurance

reversidesoftwaresolutionspt • Johannesburg

On-site
ZAR 900,000 - 1,300,000
Specialist Cybersecurity Consultant
Specialist Cybersecurity Consultant

ATS Client • Johannesburg

Hybrid
ZAR 600,000 - 900,000
Hybrid/Remote work
Certification support
Professional development
+1