
We are seeking a Penetration Tester with hands on offensive security expertise to conduct comprehensive security assessments across networks, web and mobile applications, APIs, and source code.
The role involves identifying and validating vulnerabilities, assessing security risks, providing remediation recommendations, preparing technical reports, and performing remediation verification and retesting. Strong communication skills and the ability to apply both manual and automated testing techniques are essential.
• Perform internal and external network penetration testing.
• Conduct web application penetration testing.
• Test mobile applications on Android and iOS.
• Perform API security testing, including REST and SOAP APIs.
• Perform manual and tool-assisted secure source code reviews for web, mobile, and API applications.
• Identify security weaknesses in authentication, authorization, session management, input validation, cryptography, access control, secrets management, and business logic.
• Review source code for vulnerabilities against OWASP secure coding practices and relevant PCI DSS requirements.
• Perform vulnerability assessments across in-scope systems and applications.
• Identify, validate, and safely demonstrate exploitable vulnerabilities.
• Prepare professional reports containing executive summaries, technical findings, evidence, risk ratings, affected code references, and remediation recommendations.
• Perform remediation verification and retesting.
• Clearly communicate findings to technical and non-technical stakeholders.