freehire launches on Product Hunt on 26 August.

Follow →

Penetration Tester (JD#11266)

Summary

Perform ethical hacking to find and exploit security flaws in apps, APIs, networks, and cloud systems, then write reports with remediation steps.

Job Summary

Seeking a Penetration Tester to identify, analyze, and exploit security vulnerabilities across networks, applications, and cloud environments using ethical hacking techniques. Aiming to strengthen organizational security posture by delivering actionable insights and detailed risk assessments.

Mandatory Skill-set

  • Diploma/Degree in Cybersecurity, Computer Science, Information Technology;
  • Must have 3+ years of hands-on penetration testing experience;
  • Strong experience in web application and API penetration testing;
  • Good understanding of network security, TCP/IP, HTTP/HTTPS, DNS and common network protocols;
  • Strong knowledge of OWASP Top 10 and common web vulnerabilities;
  • Hands-on experience with Linux and Windows environments;
  • Knowledge of Active Directory, privilege escalation and lateral movement;
  • Scripting/programming experience in Python, PowerShell or Bash;
  • Familiar with penetration-testing tools such as Burp Suite, Nmap, Metasploit and Kali Linux,Wireshark, BloodHound, Impacket and Nessus;
  • Strong analytical, problem-solving and report-writing skills.

Desired Skill-set

  • Experience with AWS, Azure or GCP penetration testing;
  • Certifications such as OSCP, OSWE, OSEP, CREST, GPEN or CEH.

Responsibilities

  • Conduct penetration testing across web applications, APIs, networks, infrastructure and cloud environments;
  • Perform vulnerability assessment and validate vulnerabilities through controlled exploitation;
  • Identify security weaknesses including OWASP Top 10, authentication/authorization flaws, injection vulnerabilities, misconfigurations and privilege escalation;
  • Conduct internal/external network penetration testing and assess network security controls;
  • Perform Active Directory security assessments, including privilege escalation, credential attacks and lateral movement;
  • Conduct security testing of REST APIs, mobile applications and cloud environments where applicable;
  • Develop or customise scripts, payloads and tools to support penetration-testing activities;
  • Analyse test results and determine the business impact and risk of identified vulnerabilities;
  • Prepare detailed penetration-testing reports including technical findings, evidence, risk ratings and remediation recommendations;
  • Work with security and technology teams to validate remediation and perform re-testing;
  • Keep up to date with emerging vulnerabilities, exploitation techniques, attack methodologies and security trends.

Should you be interested in this career opportunity, please send in your updated resume to apply@sciente.com at the earliest.

When you apply, you voluntarily consent to the disclosure, collection and use of your personal data for employment/recruitment and related purposes in accordance with the SCIENTE Group Privacy Policy, a copy of which is published at SCIENTE’s website (https://www.sciente.com/privacy-policy).

Confidentiality is assured, and only shortlisted candidates will be notified for interviews.

EA Licence No. 07C5639

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available