Intermediate Pentester (Code Review)
Cape Town - South Africa
Job Summary
Location: Cape Town or Johannesburg South Africa
Employment type: Full time permanent
Seniority: Intermediate - three to four years in security
- Source code review is a must for this seat not an add-on to a pentest. You read the code follow the change history and find the flaw in the logic.
- Offensive experience and code-reading ability are both required.
RedHerd is a specialist cybersecurity recruitment and advisory firm. We work with consultancies product companies vendors and enterprise security teams across South Africa the UK Europe and the United States. We are recruiting this position exclusively on behalf of our client. Their identity is shared with you during qualification before anything is submitted. We never introduce your profile without your knowledge and consent.
A deeply technical security review and consulting firm working with global clients. Their differentiator is depth: where most firms stop at a penetration test this team goes into the source code traces how a vulnerability was introduced across versions and works with the clients engineers to fix it.
Consultants are staffed onto client engagements rather than kept on internal product work so the codebases and the languages change from project to project. The team is small enough that a consultants own judgement carries real weight on an engagement.
You review source code for security defects and work with the client engineering teams. That means reading unfamiliar codebases quickly following commit history and diffs to understand how a change introduced or resolved a flaw identifying the affected functions and logic paths and proving the impact. The work is code-review led with penetration testing alongside it.
It is not a scanner-driven assurance seat and it is not a report-assembly role. Findings must be real demonstrated and explained well enough that an engineer can act on them. It is not a senior or management position either. This is a hands-on individual contributor seat though intermediate consultants here are expected to help junior reviewers find their feet.
- Review source code for security defects across unfamiliar client codebases.
- Follow commit histories and code diffs to understand how a vulnerability was introduced and whether a fix actually closed it.
- Identify the affected functions dependencies and logic paths behind a finding.
- Analyse published CVEs and their patches and look for the same pattern elsewhere in the code.
- Validate findings and demonstrate real impact rather than reporting theoretical risk.
- Carry out penetration testing and security assessment work alongside the review work.
- Produce clear well-structured written findings that a client engineer can act on.
- Explain a finding and its remediation directly to the clients technical team.
- Get up to speed on an unfamiliar language framework or codebase at the start of an engagement.
- Support and guide junior reviewers on the same engagement.
Around three to four years in security with real time spent in penetration testing or offensive security.
- Hands-on source code review for security defects. This is the must-have for this seat. You have found real vulnerabilities by reading code not only by running static analysis tooling.
- The ability to read and reason about source code in at least one compiled or JVM language on a codebase you have never seen before.
- Comfort in Git-based repositories reading commit history and diffs.
- Demonstrated offensive ability. You have found and proven real vulnerabilities and you can walk through how.
- Strong written English and genuine report-writing skill. The written finding is the deliverable.
- The ability to explain a technical finding to the engineers who own the code.
- South African work authorisation that you already hold.
Each one strengthens an application.
- C or C or other low-level code.
- Java or Scala.
- Static analysis and code property graph tooling.
- A software development background before moving into security.
- Vulnerability research or exploit development.
- Responsible disclosure bug bounty or CTF results.
- Public research technical write-ups or conference talks.
- A computer science degree or equivalent formal qualification.
Based in Cape Town or Johannesburg.
Engagement-based work with global clients so some overlap in working hours with client time zones is expected.
The exact office and remote pattern will be confirmed on the clearing call.
Well discuss the package during the Clearing Call with RedHerd.
- Work across a changing set of client codebases languages and problem domains rather than one internal product.
- A small highly technical peer group with senior reviewers on the same engagements.
- Apply on the job page. Submit your CV and answer all the screening questions.
- Clearing call with RedHerd to discuss your application and the role.
- The clients interview process which we brief you on in full before you enter it. Expect practical technical questioning on code and on offensive work.
- Background and reference checks before any offer is made.
Two things worth preparing because they are asked: your background in penetration testing or offensive security and your experience with code review including any work on C or C.
It is also worth preparing one worked example: a vulnerability you found by reading code rather than by scanning how you established the root cause and how you demonstrated impact.
If a profile or CV does not fully describe confidential work candidates are encouraged to explain their contribution without disclosing sensitive customer or employer information.
- Code review treated as a discipline in its own right not as a step inside a penetration test.
- Real depth: root cause and patch analysis not surface findings.
- A changing set of client codebases and languages rather than one stack.
- A strongly technical team where individual judgement carries weight.
- Practical ability weighted above formal qualifications in how they hire.
Applications are considered against the skills experience location and verification requirements of the role. RedHerd and our clients are committed to a fair and respectful process and do not discriminate on the basis of any protected characteristic.