Junior Penetration Tester

Summary

A Junior Penetration Tester responsible for executing security assessments on web, mobile, cloud, and IoT stacks, documenting vulnerabilities, and conducting security research. Core technologies include OWASP Top 10, Linux, networking protocols, and scripting languages.

Iterasec works with clients worldwide, helping them find vulnerabilities and secure their products. Our projects range from mobile/web applications to complex modern cloud and automotive stacks. We work with both small product companies as well as Fortune 500 enterprises.

We are looking for a talented and motivated Junior Pentester who will join our security team to work on penetration testing and vulnerability/cloud security assessment projects.

We expect a short motivation letter where you can explain your skills, achievements and motivation.

Required skills

  • Solid non-commercial cybersecurity experience, such as HTB/THM
  • Junior-level cybersecurity certifications would be a plus.
  • Comfortable with basic application security testing and common vulnerabilities (like OWASP Top 10, CWE Top 25) and cybersecurity fundamentals
  • Strong basic IT skills: Linux, networking (TCP/IP, DNS, HTTP etc.)
  • Some experience in scripting/coding languages, such as Java, JS, Python, Shell, etc.
  • Strong drive to learn and develop cybersecurity skills
  • Technical English (Intermediate)

We offer

  • Good salary + bonus system
  • Rewarding environment: brilliant team ready to share knowledge and collaborate
  • Support in obtaining professional certifications, such as BSCP, OSCP, eWPTX, cloud certifications, etc.
  • Courses and conferences which are relevant to the position are sponsored by the company.
  • We are a remote-first company with full WFH support and a flexible work schedule.

Responsibilities

  • Execute penetration tests and security assessments as part of a team, including internal/external networks, web and mobile applications, Windows and Linux environments, cloud architectures, IoT devices, and more
  • Create assessment documentation and reports, clearly identifying vulnerabilities and associated remediation steps
  • Conduct security research