As a penetration tester you can expect to do the following:- Conduct manual penetration testing against web applications APIs cloud environments infrastructure mobile applications and custom technologies.- Communicate these findings in high-quality reports and presentations- Provide security advice and partnership to engineering teams and non-technical partners- Develop scripts and tooling to augment penetration testing activities or demonstrate proof of concepts- Source code review of large sophisticated applications- Become a domain expert for colleagues in an area of security and penetration testing shape security requirements technical documentation and testing methodology. Guide others and share expertise.
In-depth knowledge of web application security system and infrastructure security
Expertise in a specialist security topic such as cloud security mobile security container security etc.
Ability to read and understand source code (Java JavaScript Go etc) and find vulnerabilities in sophisticated code bases
Strong understanding of fundamental computing database networking and security concepts
1 year of Penetration Testing experience
Passion for information security particularly in penetration testing
Ability to learn new skills concepts and technologies
Strong written and verbal communication skills ability to communicate vulnerabilities to a variety of partners
OSCP or OSWE certification (preferred)
Experience with CTFs or hacking labs
Proficiency in MacOS and other Unix based systems
Ability to grasp large sophisticated systems and context-switch when needed
Programming/scripting skills (Python JavaScript Go etc)
Knowledge of cloud architecture and security
Publications security research bug bounties or CVEs are highly regarded
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.