
Penetration Tester
Full Job Description
Role & Responsibilities
As a Penetration Tester at Breachlock, you will delve into complex computer systems and technical cybersecurity environments. Your primary focus will be on identifying security vulnerabilities within client infrastructures, web applications, and mobile applications. You'll adopt an adversary mindset to simulate sophisticated actors and achieve project-specific objectives. This role requires you to meticulously document and effectively communicate your findings and identified vulnerabilities to both technical teams and executive management. You will also contribute to the development of offensive capabilities, create internal tools and automation to streamline penetration testing execution, and conduct research to discover new vulnerabilities and develop custom tools or scripts. Furthermore, you will analyze complex scenarios and present recommendations for risk reduction when direct remediation of security vulnerabilities is not feasible.
Preferred Candidate Profile
We are looking for candidates with a degree in Information Technology, Information Systems Security, Cybersecurity, or equivalent relevant work experience. A minimum of 3 years of experience in Penetration Testing and/or Red Teaming is required. Your experience should encompass penetration testing of Web Applications, Infrastructure, and Mobile applications, as well as Vulnerability Assessments. Proficiency in Kali Linux and security tools such as Burp Suite and Metasploit is essential. You should demonstrate an ability to effectively prioritize your workload to meet deadlines with high-quality deliverables. We value hardworking individuals committed to teamwork and capable of building strong interpersonal relationships. Excellent communication skills are vital for effectively articulating ideas and scenarios both internally and with clients. Maintaining professionalism and adhering to high ethical standards at all times is paramount. A strong desire to research new security testing techniques and build automation for efficiency is highly encouraged. Preferred professional qualifications include OSCP, eJPT, or CEH. Experience with programming languages such as Python, .NET, or other interpreted or compiled languages is a plus.