Ethical HackerJob Title Ethical Hacker / Penetration Tester
Job Summary We are seeking a skilled Ethical Hacker to identify, analyze, and help remediate security vulnerabilities across applications, networks, systems, and cloud environments. The ideal candidate will perform authorized security assessments, penetration testing, vulnerability analysis, and security research to strengthen organizational defenses. You will collaborate with security engineers, developers, infrastructure teams, and compliance professionals to improve overall cybersecurity posture.
Key Responsibilities - Conduct authorized penetration testing across web applications, mobile applications, APIs, networks, cloud environments, and infrastructure.
- Identify, exploit, validate, and document security vulnerabilities using ethical hacking methodologies.
- Perform vulnerability assessments, security reviews, and risk analysis.
- Execute security testing aligned with industry frameworks such as OWASP, PTES, and NIST guidelines.
- Conduct web application security testing including authentication, authorization, injection, session management, and business logic testing.
- Perform network security assessments, including configuration reviews and vulnerability analysis.
- Analyze security findings and prepare detailed reports with risk ratings and remediation recommendations.
- Collaborate with developers, system administrators, and security teams to validate fixes and improve security controls.
- Conduct threat research and stay updated on emerging vulnerabilities, exploits, and attack techniques.
- Support red team exercises, security audits, and incident response investigations when required.
- Maintain documentation of testing methodologies, findings, and security improvements.
Required Qualifications - Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field (or equivalent practical experience).
- 2-5 years of experience in ethical hacking, penetration testing, vulnerability assessment, or security engineering.
- Strong understanding of networking concepts, TCP/IP, DNS, HTTP/HTTPS, VPNs, and firewalls.
- Hands-on experience with web application security testing and OWASP Top 10 vulnerabilities.
- Proficiency with Linux-based security environments such as Kali Linux or Parrot OS.
- Experience using penetration testing and vulnerability assessment tools.
- Knowledge of scripting languages such as Python, Bash, or PowerShell.
- Strong understanding of security principles, authentication mechanisms, encryption, and access controls.
Preferred Qualifications - Experience performing penetration tests for web applications, APIs, mobile applications, and cloud platforms.
- Knowledge of cloud security testing for AWS, Azure, or Google Cloud environments.
- Familiarity with Active Directory security assessments and enterprise network testing.
- Experience with vulnerability management platforms and security reporting tools.
- Understanding of malware analysis, exploit development, or reverse engineering concepts.
- Experience with bug bounty programs or responsible vulnerability disclosure.
- Knowledge of DevSecOps and application security practices.
Technical Skills - Kali Linux
- Burp Suite
- Metasploit Framework
- Nmap
- Wireshark
- Nessus
- OpenVAS
- OWASP ZAP
- SQLMap
- Nikto
- Gobuster
- Hydra
- Python
- Bash
- PowerShell
- Git
- Linux
- Windows Security
- Web Application Security
- API Security
- Cloud Security
Soft Skills - Strong analytical and investigative skills.
- Excellent problem-solving abilities.
- Clear technical writing and reporting skills.
- Ability to communicate security risks to technical and non-technical stakeholders.
- Strong attention to detail and ethical judgment.
- Curiosity and passion for cybersecurity research and continuous learning.
Nice to Have - Experience with red team operations, adversary simulation, or threat emulation.
- Knowledge of Active Directory attacks and defenses.
- Familiarity with container and Kubernetes security testing.
- Experience with AI security, LLM application security, or prompt injection testing.
- Contributions to security research, vulnerability disclosures, or cybersecurity communities.
- Professional certifications such as OSCP, CEH, PNPT, GPEN, GWAPT, CISSP, or Security+.
Benefits - Competitive salary and performance-based incentives.
- Comprehensive health and wellness benefits.
- Flexible or hybrid work arrangements.
- Cybersecurity training, certification, and conference support.
- Opportunity to work on advanced security assessments and real-world cybersecurity challenges.
- Collaborative environment focused on continuous security improvement.