Seeking a Penetration Tester to identify, analyze, and exploit security vulnerabilities across networks, applications, and cloud environments using ethical hacking techniques. Aiming to strengthen organizational security posture by delivering actionable insights and detailed risk assessments.
Mandatory Skill(s)
- Diploma/Degree in Cybersecurity, Computer Science, Information Technology;
- Must have 3+ years of hands-on penetration testing experience;
- Strong experience in web application and API penetration testing;
- Good understanding of network security, TCP/IP, HTTP/HTTPS, DNS and common network protocols;
- Strong knowledge of OWASP Top 10 and common web vulnerabilities;
- Hands-on experience with Linux and Windows environments;
- Knowledge of Active Directory, privilege escalation and lateral movement;
- Scripting/programming experience in Python, PowerShell or Bash;
- Familiar with penetration-testing tools such as Burp Suite, Nmap, Metasploit and Kali Linux,Wireshark, BloodHound, Impacket and Nessus;
- Strong analytical, problem-solving and report-writing skills.
Desirable Skill(s)
- Experience with AWS, Azure or GCP penetration testing;
- Certifications such as OSCP, OSWE, OSEP, CREST, GPEN or CEH.
Responsibilities
- Conduct penetration testing across web applications, APIs, networks, infrastructure and cloud environments;
- Perform vulnerability assessment and validate vulnerabilities through controlled exploitation;
- Identify security weaknesses including OWASP Top 10, authentication/authorization flaws, injection vulnerabilities, misconfigurations and privilege escalation;
- Conduct internal/external network penetration testing and assess network security controls;
- Perform Active Directory security assessments, including privilege escalation, credential attacks and lateral movement;
- Conduct security testing of REST APIs, mobile applications and cloud environments where applicable;
- Develop or customise scripts, payloads and tools to support penetration-testing activities;
- Analyse test results and determine the business impact and risk of identified vulnerabilities;
- Prepare detailed penetration-testing reports including technical findings, evidence, risk ratings and remediation recommendations;
- Work with security and technology teams to validate remediation and perform re-testing;
- Keep up to date with emerging vulnerabilities, exploitation techniques, attack methodologies and security trends.
If you are interested in this role, click on the “Apply to this job” button below or you could also write in with your CV to Shruthi GR at shruthi.gr@sciente.com quoting the job title.
Shruthi GR
Lead Technology Talent Acquisition Specialist (APAC)
Lead Technology Talent Acquisition Specialist (APAC)
