Penetration Tester

location_onJakarta, Indonesiaschedulepred 5 dňami
historyMinimálne skúsenosti:2+ rokov
schoolVzdelávanie:bakalársky titul

Popis práce

  • Conduct authorized penetration testing across Web applications, APIs, network infrastructure, eternal and internal environments, cloud environments, and other applicable technology assets
  • Perform reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities within approved testing scopes.
  • Identify vulnerabilities including authentication/authorization issues, injection, misconfiguration, access control weaknesses, insecure APIs, and other security flaws.
  • Validate vulnerabilities through controlled proof-of-concept exploitation.
  • Perform manual and automated security testing of web applications and APIs.
  • Assess common application security vulnerabilities based on OWASP methodologies.
  • Conduct testing beyond automated vulnerability scanning, including business logic and access-control testing.
  • Review application behavior and identify potential attack paths.
  • Analyze and prioritize findings based on technical severity, exploitability, and potential business impact.
  • Prepare comprehensive penetration testing reports covering executive summary, technical findings, evidence / proof of concept, risk rating, business impact, remediation recommendations
  • Present technical findings to technical and non-technical stakeholders where required.
  • Work with engineering and client teams to understand identified vulnerabilities.
  • Perform remediation validation and retesting.
  • Confirm whether vulnerabilities have been adequately addressed.
  • Stay updated on emerging vulnerabilities, exploits, attack techniques, and offensive security tools.
  • Continuously improve penetration testing methodologies and toolsets.
  • Contribute to internal knowledge sharing, playbooks, and testing methodologies.
  • Participate in client discussions to understand testing objectives, scope, and technical environments.
  • Ensure penetration testing activities are delivered according to agreed scope, methodology, timeline, and reporting requirements.
  • Maintain proper documentation of testing activities and evidence.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field.
  • Min. 2–4 years of hands-on experience in penetration testing, offensive security, vulnerability assessment, or a closely related cybersecurity role.
  • Demonstrable experience conducting penetration tests in a professional or client-facing environment.
  • Strong understanding of networking, operating systems, web technologies, authentication mechanisms, and common security vulnerabilities.
  • Strong understanding of penetration testing methodologies and vulnerability assessment.
  • Hands-on experience with web application penetration testing, API security testing, network penetration testing, vulnerability assessment, exploitation and proof-of-concept development
  • Familiarity with OWASP Top 10 and common web application vulnerabilities.
  • Working knowledge of Linux and Windows environments.
  • Understanding of TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, and network security concepts.
  • Experience with offensive security tools such as Burp Suite, Nmap, Metasploit, SQLMap, Wireshark, Gobuster/ffuf, or equivalent tools.
  • Ability to perform manual testing and not rely solely on automated scanners.
  • Ability to produce clear and technically accurate penetration testing reports.
  • Have at least one of these certifications:
  • OSCP (Offensive Security Certified Professional)
  • OSEP (Offensive Security Experienced Penetration Testers)
  • OSWA (Offensive Security Web Assessor)
  • OSWE (Offensive Security Web Expert)
  • CREST CRT (CREST Registered Penetration Tester)
  • CREST CCT INF (CREST Certified Tester Infrastructure)
  • CREST CCT APP (CREST Certified Tester Application)
  • GPEN (GIAC Penetration Tester)
  • GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)
  • GWAPT (GIAC Web Application Penetration Tester)
  • GCPN (GIAC Cloud Penetration Tester)
  • eCPPT (eLearnSecurity Certified Professional Penetration Tester)
  • eCPTX (eLearnSecurity Certified Penetration Tester eXtreme)
  • eWPT (eLearnSecurity Web Application Penetration Tester)
  • eWPTX (eLearnSecurity Web application Penetration Tester eXtreme)
  • eMAPT (eLearnSecurity Mobile Application Penetration Tester)
  • PNPT (Practical Network Penetration Tester)
  • ECSA (EC-Council Certified Security Analyst)
  • CPENT (Certified Penetration Testing Professional)
  • LPT (Licensed Penetration Tester)
  • CompTIA Pentest+
  • HTB CPTS (HTB Penetration Testing Specialist Certification)
  • CEH (Certified Ethical Hacker)

Benefits

  • Private Health Insurance
  • Pension Plan
  • Training & Development
  • Performance Bonus

Spomenuté zručnosti

Požiadajte o túto prácu

Use the application link supplied with this listing to apply to Techconnect.id. Check the destination before entering personal information.