TL;DR
Penetration Tester (Cybersecurity): Conducting security assessments on applications and systems to identify vulnerabilities and recommend corrective measures with an accent on real-world attack simulations, exploitation, and technical depth. Focus on performing technical penetration tests, identifying and exploiting vulnerabilities, and communicating findings effectively to stakeholders.
Company
hirify.global is an outsourcing company.
What you will do
- Perform technical penetration tests – including scoping, execution, and documentation.
- Identify, analyze, and exploit vulnerabilities across networks, systems, and web.
- Perform reconnaissance, information gathering, and attack path analysis.
- Communicate findings effectively to both technical and management stakeholders.
- Work with diverse environments (Operating Systems, Networks, Active Directory, authentication technologies).
- Prepare structured security reports (impact, likelihood, remediation).
Requirements
- 4+ years of experience with pentesting or in a similar position.
- Good understanding of OWASP Top 10, MITRE ATT&CK framework, and modern attack surfaces.
- Experience with infrastructure, web, and/or mobile testing.
- Good knowledge of technology such as operating systems, network, Active Directory, authentication technologies.
- Understanding of TCP/IP, DNS, HTTP/S, TLS.
- Practical understanding of common attack vectors (Injection, XSS, SSRF, Access Control, Auth flaws, etc.).
- Experience with tools like Burp Suite, Nmap, Metasploit, SQLmap, ffuf.
- Familiarity with Linux & Windows environments.
- Scripting skills (Python, Bash, PowerShell).
- Strong knowledge of networks, OS, and web security.
- Experience in penetration testing or at least CTF activities, secure software development.
- Fluent English (written and spoken).
- High motivation, ownership mindset, and willingness to continuously improve skills.
Nice to have
- Certifications (strong advantage, not mandatory): Offensive Security, Hack The Box, Zero-Point Security, Altered Security / Penetration Tester Academy.
- Technical degree or equivalent practical experience.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →