Job Description: Penetration TesterPosition Title Penetration Tester / Ethical Hacker
Job Summary We are seeking a skilled Penetration Tester to assess the security posture of our applications, networks, infrastructure, and cloud environments. The ideal candidate will perform authorized security assessments, identify vulnerabilities, simulate real-world attack scenarios, and provide detailed remediation recommendations to strengthen organizational security.
Key Responsibilities - Conduct penetration testing across web applications, mobile applications, APIs, networks, wireless environments, and cloud platforms.
- Perform vulnerability assessments and security reviews to identify weaknesses and potential attack paths.
- Execute black-box, white-box, and grey-box penetration tests based on project requirements.
- Perform reconnaissance, threat modeling, exploitation, and post-exploitation analysis within approved scopes.
- Analyze vulnerabilities and provide risk ratings based on business impact.
- Use manual testing techniques along with industry-standard security tools.
- Prepare detailed technical reports including findings, evidence, impact analysis, and remediation guidance.
- Present security findings to technical teams and stakeholders.
- Validate remediation efforts through retesting.
- Stay updated with emerging vulnerabilities, exploits, attack techniques, and security trends.
Required Technical Skills - Strong understanding of networking concepts (TCP/IP, DNS, HTTP/HTTPS, VPNs, firewalls).
- Hands-on experience with web application security testing (OWASP Top 10).
- Knowledge of operating systems including Linux and Windows.
- Experience with penetration testing tools such as:
- Burp Suite
- Nmap
- Metasploit
- Wireshark
- Nessus/OpenVAS
- SQLMap
- Kali Linux tools
- Knowledge of scripting/programming languages such as Python, Bash, PowerShell, or JavaScript.
- Understanding of vulnerability assessment, exploitation techniques, and security controls.
- Familiarity with cloud security concepts (AWS/Azure/GCP) is preferred.
Certifications (Preferred) - OSCP (Offensive Security Certified Professional)
- CEH (Certified Ethical Hacker)
- eJPT / PNPT
- CREST certifications
- Security+ or equivalent security certifications
Education & Experience - Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related field preferred.
- Experience in penetration testing, vulnerability assessment, or security consulting.
- Strong analytical and problem-solving abilities.
- Ability to document findings clearly and communicate technical risks effectively.
Soft Skills - Strong written and verbal communication skills.
- Ability to work independently and with security teams.
- Attention to detail and ethical mindset.
- Ability to explain technical vulnerabilities to both technical and non-technical audiences.
Deliverables - Penetration testing reports.
- Vulnerability assessment reports.
- Security improvement recommendations.
- Proof-of-concept demonstrations where applicable.
Role Type Full-time / Contract
Department Cybersecurity / Information Security / Offensive Security