üîê We‚Äôre Hiring: Penetration Tester | Vulnerability Analyst
üïí Employment Type: Full-Time
üíº Level: Mid-Level to Senior
We are seeking a skilled and security-focused Penetration Tester | Vulnerability Analyst to identify, assess, and help remediate security weaknesses across applications, networks, systems, and digital infrastructure. The ideal candidate will combine hands-on security testing, vulnerability assessment, risk analysis, and technical reporting to strengthen the organization's overall security posture.
üéØ Key Responsibilities‚Ä¢ Conduct authorized penetration testing across web applications, APIs, networks, servers, cloud environments, and other approved systems.
• Perform vulnerability assessments to identify security weaknesses, misconfigurations, outdated components, and exposure risks.
• Define testing scope, objectives, methodologies, rules of engagement, and assessment requirements.
• Conduct reconnaissance and asset discovery within approved testing environments.
• Assess applications and infrastructure for common security vulnerabilities and configuration weaknesses.
• Perform manual and automated security testing using appropriate industry-standard tools.
• Validate identified vulnerabilities and distinguish genuine security risks from false positives.
• Assess vulnerability severity based on technical impact, exploitability, business exposure, and risk.
• Analyze attack paths and identify potential ways multiple weaknesses could affect an environment.
• Test authentication, authorization, session management, input validation, access controls, and other security mechanisms.
• Assess APIs, web services, mobile applications, and cloud-based services where applicable.
• Conduct network and infrastructure security assessments across approved internal and external environments.
• Review system configurations, security controls, network architectures, and technical documentation.
• Perform vulnerability scanning and prioritize findings according to organizational risk-management requirements.
• Research newly disclosed vulnerabilities, security advisories, exploits, and emerging attack techniques.
• Monitor vulnerability trends and assess whether newly discovered issues affect organizational assets.
• Work with system administrators, developers, DevOps teams, and security engineers to investigate security findings.
• Provide clear technical remediation recommendations for identified vulnerabilities.
• Conduct validation or retesting activities after remediation to confirm that vulnerabilities have been appropriately addressed.
• Prepare detailed penetration-testing and vulnerability-assessment reports for technical and management audiences.
• Document evidence, affected assets, security impact, risk ratings, and recommended remediation actions.
• Present assessment findings to stakeholders and explain technical risks in business-relevant terms.
• Maintain accurate records of vulnerabilities, remediation status, testing activities, and security findings.
• Support vulnerability-management programs and contribute to security improvement initiatives.
• Help improve security testing methodologies, assessment procedures, automation, and reporting processes.
• Maintain strict confidentiality and ensure all security testing activities remain within authorized scope and approved procedures.
✅ Requirements• Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
• Previous experience in penetration testing, vulnerability assessment, security testing, or cybersecurity analysis.
• Strong understanding of network security, operating systems, web applications, APIs, databases, and cloud environments.
• Familiarity with common web and application security risks, including OWASP security principles.
• Experience using vulnerability scanners, penetration-testing tools, network-analysis tools, and security-testing frameworks.
• Knowledge of tools such as Burp Suite, Nmap, Nessus, OpenVAS, Wireshark, or comparable security platforms is advantageous.
• Understanding of TCP/IP, DNS, HTTP/HTTPS, VPNs, firewalls, authentication systems, and network architectures.
• Familiarity with Linux and Windows security environments.
• Strong understanding of vulnerability management, risk assessment, CVE/CVSS concepts, and remediation processes.
• Experience validating vulnerabilities and conducting controlled security testing.
• Basic to advanced scripting knowledge in Python, PowerShell, Bash, or similar languages is an advantage.
• Familiarity with cloud security concepts across platforms such as AWS, Azure, or Google Cloud is preferred.
• Understanding of identity and access management, endpoint security, application security, and infrastructure security.
• Strong analytical and problem-solving abilities.
• Excellent technical documentation and report-writing skills.
• Ability to communicate complex security findings clearly to technical and non-technical stakeholders.
• Strong attention to detail and ability to identify subtle security weaknesses.
• Ability to work independently while collaborating effectively with security, development, infrastructure, and operations teams.
• Strong ethical standards and strict adherence to authorized testing procedures and security policies.
• Familiarity with security frameworks and standards such as NIST, ISO 27001, CIS Controls, or similar frameworks is an advantage.
• Certifications such as OSCP, CEH, GPEN, Security+, eJPT, PNPT, or equivalent are advantageous.
üåü What We Offer‚Ä¢ Competitive salary and comprehensive employee benefits.
• Opportunities to work on diverse cybersecurity assessment and vulnerability-management projects.
• Exposure to web applications, APIs, networks, cloud infrastructure, and enterprise security environments.
• Professional training in penetration testing, vulnerability analysis, application security, and cloud security.
• Access to modern security-testing platforms, assessment tools, and cybersecurity technologies.
• Opportunities to collaborate with experienced security engineers, developers, infrastructure teams, and security leaders.
• Support for industry-recognized cybersecurity certifications and continuous professional development.
• Opportunities to participate in security improvement, risk-management, and digital transformation initiatives.
• Exposure to emerging vulnerabilities, attack techniques, defensive technologies, and security trends.
• Recognition for high-quality assessments, effective remediation guidance, and security improvements.
- • Career progression toward Senior Penetration Tester, Vulnerability Management Lead, Security Consultant, Red Team Specialist, or Cybersecurity Manager roles.