About the job Penetration Tester (Ethical Hacker) - Remote
Position Overview
We are seeking a skilled Penetration Tester (Ethical Hacker) to identify vulnerabilities, weaknesses, and security risks across applications, networks, and cloud environments. The ideal candidate will have deep knowledge of attack techniques, penetration testing tools, and security frameworks. This role requires both technical expertise and creativity to simulate real-world cyberattacks while ensuring systems remain secure.
Key Responsibilities
-
Conduct penetration tests on web applications, mobile applications, networks, APIs, cloud environments, and infrastructure.
-
Perform vulnerability assessments and exploit testing to identify risks before malicious actors do.
-
Simulate real-world attack scenarios to evaluate system resilience against cyber threats.
-
Use industry-standard tools (Burp Suite, Metasploit, Nmap, Kali Linux, Wireshark, etc.).
-
Develop and execute red team/blue team exercises in collaboration with security teams.
-
Document findings and provide detailed security reports with remediation recommendations.
-
Assist in developing secure coding practices and security awareness programs.
-
Research and stay current with the latest hacking techniques, exploits, and threat intelligence.
-
Collaborate with IT, DevOps, and security teams to remediate identified vulnerabilities.
-
Ensure compliance with security standards and regulations (ISO 27001, PCI-DSS, HIPAA, GDPR, NIST).
Qualifications
-
Bachelors degree in Cybersecurity, Computer Science, or related field (or equivalent practical experience).
-
2-5 years of hands-on experience in penetration testing, red teaming, or ethical hacking.
-
Strong understanding of OWASP Top 10, MITRE ATT&CK, CVE, and common exploit techniques.
-
Proficiency with penetration testing frameworks and tools (Kali Linux, Burp Suite, Metasploit, Cobalt Strike, Nessus, etc.).
-
Knowledge of network protocols, operating systems, databases, and cloud environments (AWS, Azure, GCP).
-
Experience in scripting and automation using Python, Bash, or PowerShell.
-
Strong analytical, problem-solving, and reporting skills.
Preferred Skills
-
Professional certifications such as:
-
Offensive Security Certified Professional (OSCP)
-
Offensive Security Experienced Professional (OSEP)
-
Certified Ethical Hacker (CEH)
-
GIAC Penetration Tester (GPEN)
-
CREST Registered Penetration Tester
-
-
Experience with Advanced Persistent Threat (APT) simulations.
-
Familiarity with reverse engineering and malware analysis.
-
Knowledge of DevSecOps and secure SDLC practices.
Benefits
-
Competitive salary and performance-based bonuses.
-
Comprehensive health and wellness benefits.
-
Professional training and certification sponsorship.
-
Flexible working arrangements (remote/hybrid).
-
Opportunity to work on challenging real-world security assessments for enterprise clients.