Penetration Tester, Delivery Senior Consultant

This role involves performing manual and automated penetration testing of web applications, APIs, and supporting infrastructure to identify and document security vulnerabilities. The candidate will provide remediation guidance and contribute to security standards. It requires experience with common testing tools and understanding of web technologies and attack vectors.

What you'd actually do

  1. Perform manual and automated penetration testing of web applications, APIs, and supporting infrastructure.
  2. Identify, validate, and document security vulnerabilities such as those in the OWASP Top 10.
  3. Conduct authenticated and unauthenticated testing across development, test, and production-like environments.
  4. Assess application security controls including authentication, authorization, session management, input validation, and encryption.
  5. Prepare clear, risk-based reports with technical findings, business impact, proof of concept, and remediation recommendations.

Skills

Required

  • Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE), GIAC Penetration Tester (GPEN), or Certified Ethical Hacker (CEH).
  • 2+ years of experience within hands-on penetration testing with a focus on web applications.
  • Strong understanding of web technologies including HTTP/S, REST APIs, JavaScript, cookies, headers, and sessions.
  • Experience identifying vulnerabilities such as SQL injection, XSS, CSRF, SSRF, IDOR, authentication flaws, and access control weaknesses.
  • Proficiency with common testing tools such as Burp Suite, OWASP ZAP, Nmap, Postman, and similar tools.
  • Experience writing professional penetration test reports for technical and non-technical audiences.
  • Familiarity with OWASP Top 10, CWE, CVSS, and secure coding principles

Nice to have

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

What the JD emphasized

  • Hands-on penetration testing experience with a focus on web applications.
  • Strong understanding of web technologies including HTTP/S, REST APIs, JavaScript, cookies, headers, and sessions.
  • Experience identifying vulnerabilities such as SQL injection, XSS, CSRF, SSRF, IDOR, authentication flaws, and access control weaknesses.
  • Proficiency with common testing tools such as Burp Suite, OWASP ZAP, Nmap, Postman, and similar tools.
  • Experience writing professional penetration test reports for technical and non-technical audiences.
  • Familiarity with OWASP Top 10, CWE, CVSS, and secure coding principles