Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Redherd.io is seeking an experienced Penetration Tester to join our Offensive Security team in South Africa. You will lead hands-on assessments across web apps, networks, and AD environments while delivering thorough reports and actionable remediation guidance to clients.
The role emphasizes a consulting mindset, strong technical reporting, and clear communication to both technical and business stakeholders.
We're looking for an experienced Penetration Tester with 3-5+ years of hands-on offensive security experience within a consulting or professional services environment. The successful candidate will have proven experience performing web application, infrastructure, internal and external network, and Active Directory penetration testing while producing high-quality technical reports and remediation guidance. Strong proficiency with Burp Suite, Kali Linux, Metasploit, Nmap, Nessus, BloodHound, Impacket, and related offensive security tooling is expected, alongside scripting experience in Python, Bash, or PowerShell. Candidates should demonstrate a solid understanding of the OWASP Top 10, modern attack methodologies, and common enterprise technologies. Relevant certifications such as OSCP, PNPT, CRTP, CRTE, eCPPT, or eJPT are highly desirable. Excellent client communication, report writing, and the ability to manage multiple consulting engagements are essential.
Our client is one of South Africa’s leading cybersecurity consultancies, delivering offensive security, advisory, managed security, and incident response services to enterprise organisations across multiple industries.
Working alongside experienced consultants, you will perform high-quality penetration testing engagements, identify security weaknesses, and provide clients with practical recommendations to strengthen their security posture.
Our client is seeking an experienced Penetration Tester to join their growing Offensive Security team.
This role is suited to someone who enjoys technical assessments across web applications, internal and external infrastructure, Active Directory environments, cloud platforms, and network security. You will work on multiple client engagements while producing high-quality technical reports and remediation guidance.
The ideal candidate has a consulting mindset, enjoys solving complex security problems, and can confidently communicate technical findings to both technical and business stakeholders.
Experience with one or more of:
One or more of the following:
Highly Valued
Advantageous