Job Summary
We are looking for an experienced Offensive Security / Penetration Testing professional to identify, assess, and validate security vulnerabilities across enterprise technology environments. This role will be responsible for conducting security assessments and penetration testing across Web Applications, Mobile Applications, APIs, Network Infrastructure, and Enterprise Systems, while providing actionable recommendations to strengthen the organization's overall security posture.
The ideal candidate should have a strong attacker mindset, hands-on experience in offensive security, and the ability to communicate technical security findings effectively to both technical and business stakeholders.
Key Responsibilities
- Conduct Penetration Testing and Vulnerability Assessments across applications, APIs, mobile applications, networks, infrastructure, and enterprise systems.
- Perform Web Application Security Testing based on OWASP methodologies and industry best practices.
- Conduct Red Team and Purple Team exercises to simulate real-world attacks and evaluate the effectiveness and readiness of security controls.
- Identify, validate, and analyze security vulnerabilities, assess associated risks, and provide practical remediation recommendations.
- Perform Threat Modeling, Security Assessments, and Security Reviews for applications, systems, and technology solutions.
- Support Application Security, Secure Coding, and Source Code Review activities to identify security weaknesses throughout the software development lifecycle.
- Integrate security testing into CI/CD pipelines and DevSecOps processes to promote security-by-design practices.
- Develop scripts, tools, and automation to improve the efficiency and scalability of security testing activities.
- Prepare comprehensive security assessment reports and present technical findings, risks, and remediation recommendations to both technical and business stakeholders.
- Collaborate closely with Blue Team, Infrastructure, Development, and other technology teams to strengthen security controls and improve overall security posture.
- Support Incident Response activities and continuously monitor emerging threats, vulnerabilities, and attack techniques.
- Conduct retesting and validation to ensure identified vulnerabilities have been effectively remediated.
Qualifications
- Bachelor's degree or higher in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or a related field.
- 3–5+ years of hands-on experience in Penetration Testing, Offensive Security, Application Security, or Vulnerability Assessment.
- Strong knowledge of Network Security, Web Application Security, Mobile Security, API Security, and Ethical Hacking.
- Hands-on experience with security tools such as Burp Suite, Nmap, Nessus, Metasploit, OWASP ZAP, and Kali Linux.
- Programming or scripting experience with languages such as Python, PHP, Node.js, or equivalent.
- Strong analytical and problem-solving skills with the ability to think from an attacker's perspective.
- Ability to analyze and communicate technical security findings clearly to both technical and non-technical stakeholders.
- Strong teamwork, communication, and time-management skills, with the ability to work effectively under pressure.
- Good command of spoken and written English.
Certifications
Required
- OSCP (Offensive Security Certified Professional)
Preferred
- GPEN (GIAC Penetration Tester)
- CompTIA PenTest+
- BSCP (Burp Suite Certified Practitioner)
Preferred Experience
Candidates with experience in the following areas will be highly preferred:
- Red Team / Purple Team Operations
- Web, Mobile, and API Penetration Testing
- Cloud Security
- DevSecOps / CI/CD Security
- Source Code Review
- Threat Modeling
- Vulnerability Management
- Security Testing Automation
- Exploit Development or Advanced Attack Techniques
Ideal Candidate
The ideal candidate is an Offensive Security professional who can manage the security testing lifecycle from end to end:
Identify Vulnerabilities → Exploit & Validate → Assess Risk → Recommend Remediation → Retest → Improve Security Controls
You should be comfortable working closely with Cybersecurity, Development, Infrastructure, and Technology teams, while continuously exploring new vulnerabilities, attack techniques, and emerging threats to strengthen the organization's security posture.