We Are Looking For a Penetration tester to simulate cyberattacks to identify and report security flaws. They examine the target website, system, mobile applications, or product for weaknesses through a variety of tools based on what they find during reconnaissance and during the test. the Penetration testing team is primarily responsible for following penetration test strategies for system, network, web & mobile apps. We are looking for applicants at different seniority levels.
Description:
- Demonstrates general knowledge of concepts such as OWASP Top 10, vulnerability scanning, and penetration testing methodologies (OWASP, PTES, OSINT).
- Conducts and assists with automated and manual security testing of applications, infrastructure, and public cloud platforms to identify and validate vulnerabilities.
- Retests previously discovered vulnerabilities to confirm successful remediation.
- Develops and maintains documentation such as procedures, assets, communication, etc.
- Performs quality assurance of penetration testing and vulnerability scan artifacts.
- Contribute to the enhancement of the penetration testing program.
- Provides technical evaluation and analysis. Supports activities, processes, and tools needed to improve the overall security posture of the organization.
- Applies security concepts, reviews information executes defined tasks, analyzes requirements, reviews logs, and creates documentation.
- Performs investigation and data loss prevention, data manipulation, and coordination of activities.
- Performs actions to address or mitigate risks and vulnerabilities.
- Reviews and defines controls.
- Advises on more complex security procedures and products for clients, security administrators, and network operations.
- Participates in the enforcement of control security risks and threats; the potential of one more control is subject to manager discretion.
- Shares knowledge with staff.
- Conducts security assessments and other information security routines consistently.
- Investigates and recommends corrective actions for data security related to established guidelines.