The Penetration Testing Engineer will conduct hands-on security assessments across various platforms, including web applications, mobile applications, web services/APIs, and networks. They will utilize both commercial and open-source tools such as Burp Professional, Nmap, Kali, and Metasploit. The engineer will be responsible for creating security threat models, test plans, and translating complex security threats into understandable procedures for developers and administrators. The role requires a strong understanding of application development processes and proficiency in at least one programming or scripting language. They should also have in-depth knowledge of current information security threats.
Good To Have:- Certification on CEH (Certified Ethical Hacker).
- OSCP (Offensive Security Certified Professional) is desirable.
Must Have:- Experience with testing frameworks for web apps, mobile, web services.
- Experience with commercial and open-source tools like Burp, Nmap, Kali.
- Experience with OWASP and OSSTMM methodologies and tools.
- Experience in preparing security threat models and test plans.
- Translate complex security threats into simpler procedures.