We are seeking a skilled and driven penetration tester with a hacker mindset to proactively simulate real-world attacks to identify, assess, and exploit security vulnerabilities.
You’ll be part of a fast-paced security team, expected to think like an adversary while maintaining ethical standards and compliance. You must be capable of both automated and manual testing, custom script writing, and producing detailed yet understandable reports.
Key Responsibilities
Conduct black-box, gray-box, and white-box penetration tests on: Web apps, Mobile apps, APIs.
Perform social engineering and phishing simulation campaigns
Develop and execute custom exploits where necessary
Document proof-of-concept exploits and provide risk-ranked findings
Conduct red team exercises simulating advanced persistent threats (APT)
Analyze security findings from Hacker One and recreate vulnerabilities
Collaborate with developers, Appsec Team, DevOps, and product teams to provide remediation guidance
Stay current on CVEs, exploits, hacker tools, and threat actor techniques (TTPs)
Weekly updates and debriefs with stakeholders
Manual Application and Api Penetration testing based on Owasp top 10 (Mobile,Web,Api)
Minimum Requirements
Proven experience in offensive security or ethical hacking
5 years of experience
Demonstrated history with Bug Bounty programs or CTF competitions
Deep understanding of web technologies, cloud platforms, and modern infrastructure
Ability to write and explain exploits or security PoCs clearly
Strong report writing and communication skills
Tools and Platforms (it’s expected to have knowledge of how to use at least one of each of the listed tools):