Penetration Tester (AEV)
About BreachLock
BreachLock is a fast-growing cybersecurity company focused on modern, scalable, and continuous security testing solutions. We operate at the intersection of offensive security, automation, and cloud-native engineering—building systems that are both resilient and intelligent.
Description
- Work closely with Breach360, a security testing product, to validate and improve the quality, accuracy, and effectiveness of security assessment results.
- Review and validate vulnerabilities, attack paths, evidence, and recommendations generated by the product across Web, Mobile, Infrastructure, Cloud, and other environments.
- Work with clients to understand their environment and objectives, help them interpret Breach360 results, and ensure findings align with their expectations and security requirements.
- Benchmark Breach360's output across different assets, technologies, and scenarios to identify gaps, false positives/negatives, and opportunities for improvement.
- Collaborate with Engineering and Product teams to provide actionable feedback and help improve detection, attack coverage, prioritization, reporting, and overall product capabilities.
- Research new vulnerabilities and attack techniques and develop PoCs, scripts, test cases, or automation to improve the product.
- Recommend practical security testing and remediation approaches from a client and security practitioner perspective.
Requirements
- Degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
- 3+ years of experience in Penetration Testing, Red Teaming, Application Security, or Security Consulting.
- Strong hands-on experience with Web Applications, Infrastructure, Mobile Applications, APIs, and Vulnerability Assessments.
- Strong understanding of tools such as Kali Linux, Burp Suite, Nmap, Metasploit, and other security testing tools.
- Ability to validate automated security findings, identify false positives/negatives, and assess real-world exploitability and impact.
- Experience working with security products, automation, or engineering teams to improve testing capabilities and product output is a strong plus.
- Strong client-facing communication and ability to translate technical findings into practical recommendations.
- Strong analytical, troubleshooting, and research skills with a mindset for continuously improving security testing.
- Programming/scripting experience in Python, .NET, or similar languages.
- Preferred certifications: OSCP, OSCP+, CRTP.
Benefits
- Private Health Insurance
Skills
As published by workable · 10 questions
Basics
First name, Last name, Email, Headline, Phone, Address, Photo, Education, Experience, Summary, Resume, Cover letter
Short answers (5)
- What is your Current CTC (LPA)?
- Please mention your expected annual CTC (LPA)
- Please mention your current notice period.
- What is your Current CTC (LPA)?
- Please mention your expected annual CTC (LPA)
Pick from a list (5)
- Do you have any of the following certifications?
- 5+ years of experience in Penetration Testing and/or Red Teaming;
- Experience with penetration testing like Web Applications, Infrastructure, mobile applications, and Vulnerability Assessments;
- Do you have any of the following certifications?
- What is your notice period / earliest availability to join?