Ethical Hacker
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Ethical Hackers to conduct authorised penetration testing, offensive security assessments and controlled security simulations across complex enterprise IT environments.
The successful candidates will be responsible for identifying, validating and reporting exploitable security vulnerabilities affecting enterprise networks, applications, operating systems, cloud infrastructure, identity platforms and other critical information technology assets.
This role requires strong hands-on expertise in ethical hacking, penetration testing, vulnerability exploitation, offensive security methodologies, security assessment tools and technical vulnerability reporting.
The ideal candidates will have proven experience conducting structured penetration tests, identifying weaknesses that could be exploited by malicious actors, demonstrating potential business impact and recommending practical remediation measures.
Candidates must be able to work within formally authorised testing scopes, apply recognised penetration testing methodologies and communicate technical findings effectively to both technical teams and business stakeholders.
This is a specialist offensive cybersecurity role requiring demonstrable practical penetration testing experience rather than general vulnerability scanning, security monitoring or theoretical ethical hacking knowledge.
Key Responsibilities
Penetration Testing and Ethical Hacking
- Plan and conduct authorised penetration testing assessments across enterprise IT environments.
- Perform internal and external network penetration testing.
- Identify, validate and safely demonstrate exploitable security vulnerabilities.
- Conduct controlled security assessments against servers, applications, endpoints and network infrastructure.
- Assess the effectiveness of existing cybersecurity controls.
- Develop structured testing plans based on agreed scope, objectives and rules of engagement.
- Perform vulnerability enumeration, technical analysis and controlled exploitation.
- Identify potential attack paths and security weaknesses affecting critical business systems.
- Document testing evidence, technical findings and potential business impact.
- Recommend practical remediation measures to strengthen organisational security.
Network and Infrastructure Penetration Testing
- Conduct security assessments of enterprise networks, servers and infrastructure.
- Identify weaknesses in network configurations, exposed services and security controls.
- Assess network segmentation and access restrictions.
- Investigate insecure protocols, weak authentication and misconfigured services.
- Evaluate security weaknesses affecting Windows and Linux systems.
- Assess firewall configurations and network security architecture within authorised scope.
- Identify potential privilege escalation and lateral movement opportunities.
- Validate network vulnerability findings through controlled testing.
- Prepare technical recommendations for infrastructure remediation.
- Collaborate with infrastructure and network security teams to address identified weaknesses.
Web Application and API Security Testing
- Conduct authorised penetration testing of web applications and APIs.
- Identify common application security vulnerabilities.
- Assess authentication, authorisation and session management controls.
- Test application input validation and security configurations.
- Identify insecure access controls and potential sensitive information exposure.
- Evaluate API authentication and authorisation mechanisms.
- Assess application security against recognised OWASP guidance.
- Analyse application security weaknesses and potential exploitation paths.
- Document application security findings and remediation recommendations.
- Collaborate with application development teams to validate corrective actions.
Active Directory and Identity Security Assessments
- Conduct authorised security assessments of Microsoft Active Directory environments.
- Identify insecure identity configurations and excessive privileges.
- Assess authentication controls and privileged account security.
- Investigate potential credential exposure and identity-related vulnerabilities.
- Evaluate opportunities for privilege escalation and lateral movement.
- Assess Group Policy and directory service security configurations.
- Review identity-related attack paths within approved testing scope.
- Support remediation of identified identity security weaknesses.
- Collaborate with identity and infrastructure security specialists.
Cloud Security Penetration Testing
- Conduct authorised security assessments of supported cloud environments.
- Identify cloud infrastructure misconfigurations and security weaknesses.
- Assess cloud identity and access management controls.
- Review permissions, exposed services and insecure configurations.
- Evaluate potential attack paths affecting cloud-hosted workloads.
- Assess cloud application and API security.
- Support security testing across hybrid and multicloud environments.
- Conduct cloud security testing in accordance with applicable provider policies and agreed rules of engagement.
- Recommend improvements to cloud security architecture and configurations.
Vulnerability Research and Exploit Validation
- Research relevant vulnerabilities, security advisories and emerging exploitation techniques.
- Analyse vulnerability scan results and validate potentially exploitable findings.
- Assess vulnerability severity, exploitability and potential business impact.
- Conduct controlled proof-of-concept testing where authorised.
- Identify security weaknesses that automated scanning tools may overlook.
- Evaluate potential attack chains involving multiple vulnerabilities.
- Support prioritisation of remediation based on validated technical risk.
- Maintain accurate technical evidence and testing records.
- Keep current with relevant offensive security research and techniques.
Red Team and Adversary Simulation Support
- Participate in authorised Red Team exercises and adversary simulation activities.
- Support controlled testing of organisational detection and response capabilities.
- Apply relevant attacker tactics, techniques and procedures during approved assessments.
- Map assessment activities and findings to the MITRE ATT&CK framework.
- Collaborate with Blue Team and SOC personnel during Purple Team exercises.
- Identify gaps in security monitoring and detection capabilities.
- Support validation of security controls against realistic attack scenarios.
- Document testing outcomes and security improvement opportunities.
Penetration Testing Reporting and Remediation
- Prepare comprehensive penetration testing reports.
- Document identified vulnerabilities, affected assets, supporting evidence and potential impact.
- Assign appropriate technical severity and risk ratings.
- Provide clear and actionable remediation recommendations.
- Present findings to technical teams and relevant stakeholders.
- Explain technical risks in terms of potential business impact.
- Conduct remediation verification and retesting.
- Maintain accurate assessment documentation and evidence.
- Track identified vulnerabilities through the remediation process.
- Support continuous improvement of enterprise security testing methodologies.
Security Governance and Professional Testing Standards
- Ensure all penetration testing activities are formally authorised.
- Work within documented testing scopes and rules of engagement.
- Protect confidential information obtained during security assessments.
- Follow appropriate evidence-handling and reporting procedures.
- Avoid unnecessary disruption to production systems.
- Escalate critical findings through approved security channels.
- Apply recognised penetration testing standards and methodologies.
- Maintain professional ethical hacking practices.
- Support relevant cybersecurity assurance and compliance requirements.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security, Network Engineering or a related discipline.
- Typically 3–5 years of relevant hands-on experience in penetration testing, ethical hacking, offensive security or a closely related technical cybersecurity specialisation.
- Proven practical experience conducting authorised penetration tests against enterprise systems and infrastructure.
- Strong understanding of penetration testing methodologies and offensive security techniques.
- Practical experience with network penetration testing and vulnerability validation.
- Experience identifying and assessing exploitable security weaknesses.
- Hands-on experience using recognised penetration testing tools.
- Strong understanding of Windows and Linux operating systems.
- Good knowledge of TCP/IP networking, DNS, HTTP/HTTPS and enterprise network protocols.
- Understanding of Active Directory security and common identity-related weaknesses.
- Experience assessing web applications or APIs for security vulnerabilities.
- Familiarity with OWASP security testing guidance.
- Experience preparing professional penetration testing reports.
- Ability to explain vulnerability severity, exploitability and business impact.
- Understanding of security assessment scope, authorisation and rules of engagement.
- Experience with cloud penetration testing would be advantageous.
- Strong technical troubleshooting, analytical and investigative abilities.
Technical Skills and Competencies
Penetration Testing Methodologies
- Penetration Testing Execution Standard (PTES)
- OWASP Web Security Testing Guide
- OWASP Top 10
- OWASP API Security Top 10
- NIST SP 800-115
- MITRE ATT&CK
- Authorised security assessment planning
- Rules of engagement
- Vulnerability identification and validation
- Controlled exploitation
- Attack path analysis
- Penetration testing reporting
- Remediation verification
Penetration Testing Tools
Practical experience with relevant tools such as:
- Kali Linux
- Burp Suite Professional
- Nmap
- Nessus
- OpenVAS / Greenbone
- Metasploit Framework
- Wireshark
- Nikto
- Gobuster
- ffuf
- OWASP ZAP
- BloodHound
- Impacket
- Other recognised penetration testing and security assessment tools
Network Penetration Testing
- TCP/IP networking
- Network reconnaissance
- Service enumeration
- Network vulnerability assessment
- Authentication security testing
- Network segmentation assessment
- Firewall security assessment
- Windows and Linux security weaknesses
- Network protocol analysis
- Controlled privilege escalation testing
- Lateral movement risk assessment
- Network attack path analysis
Web Application and API Security
- OWASP Top 10
- OWASP API Security Top 10
- Broken access control
- Injection vulnerabilities
- Cross-site scripting (XSS)
- Server-side request forgery (SSRF)
- Authentication weaknesses
- Session management security
- Insecure configurations
- API authorisation testing
- Sensitive data exposure
- Web application security testing
- Secure software development fundamentals
Active Directory and Identity Security
- Microsoft Active Directory
- Microsoft Entra ID fundamentals
- Windows authentication
- Kerberos
- NTLM
- Privileged account security
- Group Policy security
- Identity misconfiguration assessment
- Credential exposure risks
- Privilege escalation assessment
- Active Directory attack path analysis
- Identity and access control testing
Cloud Security Testing
- Microsoft Azure
- Amazon Web Services (AWS)
- Google Cloud Platform fundamentals
- Cloud identity and access management
- Cloud workload security
- Cloud configuration assessment
- Cloud permission reviews
- Cloud application security
- Cloud API security
- Hybrid infrastructure security
- Cloud penetration testing scope and provider requirements
Operating Systems and Infrastructure
- Windows Server
- Windows 10 and Windows 11
- Linux
- Kali Linux
- Active Directory
- Virtualisation technologies
- Enterprise networking
- Firewalls
- VPN technologies
- Web servers
- Databases
- Enterprise authentication systems
Scripting and Programming
- Python
- PowerShell
- Bash
- JavaScript fundamentals
- SQL fundamentals
- REST APIs
- JSON
- Regular expressions
- Security testing automation
- Basic exploit code analysis
- Scripting for security assessments
Vulnerability Assessment and Risk Analysis
- Vulnerability discovery
- CVE analysis
- CVSS scoring
- Exploitability assessment
- Proof-of-concept validation
- Security misconfiguration assessment
- Vulnerability prioritisation
- Attack surface analysis
- Technical risk assessment
- Remediation recommendations
- Vulnerability retesting
Security Reporting and Documentation
- Penetration testing reports
- Executive summaries
- Technical vulnerability descriptions
- Evidence documentation
- Risk severity ratings
- Remediation guidance
- Assessment methodology documentation
- Security findings presentation
- Retesting and closure reports
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- Offensive Security Certified Professional (OSCP)
- Offensive Security Web Expert (OSWE)
- Offensive Security Experienced Penetration Tester (OSEP)
- Certified Ethical Hacker (CEH)
- Certified Penetration Testing Professional (CPENT)
- GIAC Penetration Tester (GPEN)
- GIAC Web Application Penetration Tester (GWAPT)
- GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
- CompTIA PenTest+
- CompTIA Security+
- CREST Registered Penetration Tester (CRT)
- CREST Certified Penetration Tester (CCT)
- eLearnSecurity Junior Penetration Tester (eJPT)
- eLearnSecurity Certified Professional Penetration Tester (eCPPT)
- Relevant cloud security or offensive cybersecurity certifications
Key Personal Attributes
- Strong analytical and technical problem-solving abilities.
- Excellent attention to detail.
- Inquisitive and investigative mindset.
- Ability to identify complex security weaknesses and attack paths.
- Strong understanding of professional ethics and confidentiality.
- Ability to conduct security assessments methodically and responsibly.
- Excellent technical documentation and reporting skills.
- Ability to explain complex cybersecurity findings clearly.
- Strong collaboration skills across technical and business teams.
- Ability to manage multiple security assessments and deadlines.
- Commitment to continuous technical learning and professional development.
- High levels of accountability and professional integrity.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their practical ethical hacking, penetration testing and offensive security experience, together with copies of relevant academic qualifications and professional certifications.
Candidates should specifically highlight:
- Enterprise penetration testing assessments they have personally conducted.
- Experience with internal and external network penetration testing.
- Web application and API security testing experience.
- Active Directory and identity security assessments completed.
- Cloud penetration testing experience, where applicable.
- Penetration testing tools used professionally.
- Examples of vulnerabilities identified and validated during authorised assessments.
- Experience developing professional penetration testing reports.
- Experience conducting remediation verification and retesting.
- Participation in authorised Red Team or Purple Team exercises.
- Scripting and automation skills relevant to penetration testing.
- The size and complexity of enterprise environments assessed.
- Relevant ethical hacking, penetration testing and offensive security certifications.
Important: This is a specialist Ethical Hacker opportunity requiring demonstrable hands-on penetration testing and offensive security experience. General IT support, basic vulnerability scanning, SOC monitoring or theoretical ethical hacking knowledge without substantial practical penetration testing experience will not be sufficient.
Please note: This is a provisional recruitment specification prepared pending confirmation of the client's detailed technical requirements. The preferred testing specialisations, minimum experience, qualifications, certifications, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.