Job Summary
Job Responsibilities
1. Working with a diverse range of colleagues to define security testing activities
(scope) across target applications and infrastructure
2. Continuous improvement and best practices to promote continuous improvement
of penetration testing methodologies and processes
3. Delivery of technical reports and documentation
4. Communication of security vulnerabilities and exposures to internal stakeholders
5. Perform penetration testing and vulnerability assessments, including the triage of
findings to determine key exposures. Expanding upon this responsibility, you will
also be required to perform:, cloud
o Tests against various technical assets (applications, networks, cloud), as
expanded upon below
o Security Audits
o Analyse Security Policies
o Write Security Assessment Reports
Your Experience & Qualifications
1. At least 5+ years exp.
2. Extensive experience as a penetration tester or security analyst, with experience in
large organisations.
3. Extensive experience penetration testing various assets, including but not limited
to; web applications, mobile applications, networks/infrastructure, and cloud
services. You should highlight any key strengths across these disciplines.
Key Responsibilities
1. To design and execute comprehensive test plans and test cases for assigned software modules and features.
2. To utilize automation tools and frameworks to increase test efficiency and coverage to perform various types of testing (functional, regression, usability, and API testing).
3. To identify, reproduce, and document software defects according to established procedures.
4. To proactively partner with developers to analyze, prioritize, and verify defect resolutions, while actively participating in test reviews to drive continuous improvement and best practice sharing.
5. To stay up-to-date with the latest testing trends and technologies and contribute to the creation and maintenance of test automation frameworks/ libraries.
Skill Requirements
A clear understanding of both manual and automated penetration testing
techniques, including knowledge of common penetration testing tools and the
impacts they have on systems.
5. Fluent understanding of cloud technologies (AWS, Azure)
6. A comprehensive understanding of Penetration Testing frameworks and
methodologies (OWASP, OSSTTMM, WAHH).
7. Advanced problem-solving skills
8. Excellent written and verbal communication skills – with experience writing and
conveying complex penetration testing findings and their associated risks through
reports to stakeholders; findings writeups, or verbal discussions.
9. Ability to attend to the detail on multiple concurrent tasks while meeting various
deadlines.
10. Industry certifications such as OSCP, OSWE, CREST (CRT, CCT), or equivalent are
highly desired
11. Training on self-development platforms (i.e. HackTheBox, Pentesterlabs, wechall,
etc.)
Nice to have:
1. Experience working in large enterprise organisations e.g. banking
2. Exposure to Microservices, Web and Cloud technologies
3. Degree in Computer Science, Information Security or similar