Pentester WebAPP and API
- Experience: ~5+ years of hands-on offensive security experience, ideally within a cybersecurity consultancy or multi-client delivery environment.
- Core Depth: Proven expertise in at least three domains: web applications, network, mobile, or Active Directory testing.
- Tooling Infrastructure: Mastery of industry-standard tools (Burp Suite, Nmap, Metasploit, BloodHound, Impacket, CrackMapExec/NetExec, Cobalt Strike, Frida, etc.).
- Certifications (Minimum of ONE required):
- OSCP (Offensive Security Certified Professional)
- CRTP / CRTO (Active Directory/Red Team)
- CREST CRT / CPSA (CCT App or Infra strongly preferred)
- Soft Skills: Exceptional report-writing skills and fluent professional English.
Highly Desirable / Nice to Have
- Advanced certifications (OSEP, OSWE, OSED, CRTE, SANS GXPN/GWAPT, or Cloud offensive certs).
- Prior experience within a Big 4 firm or an established boutique security consultancy.
- Hands-on exposure to AWS/Azure/GCP cloud environments and Kubernetes/containers.
- Active community presence: Published research, CVEs, open-source tooling contributions, conference talks, or top CTF achievements.