Penetration Tester
location_onJakarta, Indonesiaschedule5天前
history最低经验:2+ 年
school学历:学士
职位描述
- Conduct authorized penetration testing across Web applications, APIs, network infrastructure, eternal and internal environments, cloud environments, and other applicable technology assets
- Perform reconnaissance, vulnerability discovery, exploitation, and post-exploitation activities within approved testing scopes.
- Identify vulnerabilities including authentication/authorization issues, injection, misconfiguration, access control weaknesses, insecure APIs, and other security flaws.
- Validate vulnerabilities through controlled proof-of-concept exploitation.
- Perform manual and automated security testing of web applications and APIs.
- Assess common application security vulnerabilities based on OWASP methodologies.
- Conduct testing beyond automated vulnerability scanning, including business logic and access-control testing.
- Review application behavior and identify potential attack paths.
- Analyze and prioritize findings based on technical severity, exploitability, and potential business impact.
- Prepare comprehensive penetration testing reports covering executive summary, technical findings, evidence / proof of concept, risk rating, business impact, remediation recommendations
- Present technical findings to technical and non-technical stakeholders where required.
- Work with engineering and client teams to understand identified vulnerabilities.
- Perform remediation validation and retesting.
- Confirm whether vulnerabilities have been adequately addressed.
- Stay updated on emerging vulnerabilities, exploits, attack techniques, and offensive security tools.
- Continuously improve penetration testing methodologies and toolsets.
- Contribute to internal knowledge sharing, playbooks, and testing methodologies.
- Participate in client discussions to understand testing objectives, scope, and technical environments.
- Ensure penetration testing activities are delivered according to agreed scope, methodology, timeline, and reporting requirements.
- Maintain proper documentation of testing activities and evidence.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field.
- Min. 2–4 years of hands-on experience in penetration testing, offensive security, vulnerability assessment, or a closely related cybersecurity role.
- Demonstrable experience conducting penetration tests in a professional or client-facing environment.
- Strong understanding of networking, operating systems, web technologies, authentication mechanisms, and common security vulnerabilities.
- Strong understanding of penetration testing methodologies and vulnerability assessment.
- Hands-on experience with web application penetration testing, API security testing, network penetration testing, vulnerability assessment, exploitation and proof-of-concept development
- Familiarity with OWASP Top 10 and common web application vulnerabilities.
- Working knowledge of Linux and Windows environments.
- Understanding of TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, and network security concepts.
- Experience with offensive security tools such as Burp Suite, Nmap, Metasploit, SQLMap, Wireshark, Gobuster/ffuf, or equivalent tools.
- Ability to perform manual testing and not rely solely on automated scanners.
- Ability to produce clear and technically accurate penetration testing reports.
- Have at least one of these certifications:
- OSCP (Offensive Security Certified Professional)
- OSEP (Offensive Security Experienced Penetration Testers)
- OSWA (Offensive Security Web Assessor)
- OSWE (Offensive Security Web Expert)
- CREST CRT (CREST Registered Penetration Tester)
- CREST CCT INF (CREST Certified Tester Infrastructure)
- CREST CCT APP (CREST Certified Tester Application)
- GPEN (GIAC Penetration Tester)
- GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)
- GWAPT (GIAC Web Application Penetration Tester)
- GCPN (GIAC Cloud Penetration Tester)
- eCPPT (eLearnSecurity Certified Professional Penetration Tester)
- eCPTX (eLearnSecurity Certified Penetration Tester eXtreme)
- eWPT (eLearnSecurity Web Application Penetration Tester)
- eWPTX (eLearnSecurity Web application Penetration Tester eXtreme)
- eMAPT (eLearnSecurity Mobile Application Penetration Tester)
- PNPT (Practical Network Penetration Tester)
- ECSA (EC-Council Certified Security Analyst)
- CPENT (Certified Penetration Testing Professional)
- LPT (Licensed Penetration Tester)
- CompTIA Pentest+
- HTB CPTS (HTB Penetration Testing Specialist Certification)
- CEH (Certified Ethical Hacker)
Benefits
- Private Health Insurance
- Pension Plan
- Training & Development
- Performance Bonus
提及的技能
申请该职位
Use the application link supplied with this listing to apply to Techconnect.id. Check the destination before entering personal information.
