As a Penetration Tester, you will play a key role in delivering high-quality security assessments for our clients, identifying security vulnerabilities and producing clear, actionable remediation guidance.
Requirements
- Conduct manual penetration testing against web applications, mobile applications, APIs, infrastructure and cloud environments.
- Configure and operate penetration testing tools and scripts to identify vulnerabilities and validate exploitability.
- Document security findings and produce clear, high-quality reports including detailed remediation guidance.
- Develop proof-of-concept exploits demonstrating the real-world impact of vulnerabilities.
- Participate in client calls including kickoff meetings, technical walkthroughs and remediation discussions.
- Collaborate with project managers and testers to ensure engagements are delivered on time and at a high level of quality.
- Perform internal QA reviews of penetration testing deliverables when required.
- Support vulnerability retesting to validate remediation efforts.
- Contribute to improvement of internal tools, methodologies and testing frameworks.
- Mentor junior testers and provide technical guidance when applicable.
- Participate in knowledge sharing activities such as internal training, presentations or research initiatives.
- Strong understanding of networks, operating systems and web/mobile application architectures.
- Familiarity with common vulnerabilities including XSS, SQL Injection, XXE, Deserialization, Path Traversal, SSRF, RCE and authentication flaws.
- Experience testing web/mobile applications and APIs (REST, SOAP, graphQL).
- Familiarity with common penetration testing tools such as Burp Suite, Nessus, nmap.
- Experience with scripting languages such as Python, Bash, PowerShell or Perl.
- Ability to design and document practical remediation guidance for vulnerabilities.
- Strong technical writing skills with the ability to translate technical issues into business risk.
- Experience working with Linux and Windows environments.
- Understanding of penetration testing methodologies such as OWASP, MITRE ATT&CK, OSSTMM and NIST frameworks.
- Ability to work independently and manage testing tasks with minimal supervision.
- Strong communication skills with clients and internal teams.
- Ability to manage sensitive information and maintain strict confidentiality.
- Familiarity with office tools such as Outlook, Teams, Excel and Word.
Benefits
- Generous Paid Time Off
- 401k Matching
- Retirement Plan
- Visa Sponsorship
