обновлено 1 день назад
Penetration Testing Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Penetration Testing Analyst (Cybersecurity): Performing hands-on web, API, mobile, and infrastructure security testing with an accent on manual vulnerability discovery, exploitation, risk assessment, and remediation reporting. Focus on researching new attack techniques, mapping attack paths, validating fixes, and supporting foundational red team and adversary simulation exercises.
Location: Taguig City, National Capital Region (Manila), Philippines
Company
provides financial security, insurance, health, and related services to clients, families, and communities worldwide.
What you will do
- Perform web, API, mobile, and infrastructure penetration testing across enterprise applications.
- Identify, exploit, and validate vulnerabilities through manual testing and industry-standard tools.
- Test applications and systems using established methodologies and security frameworks such as OWASP.
- Produce structured reports covering root cause, business impact, risk ratings, and practical remediation recommendations.
- Research new vulnerabilities, exploits, and attack techniques; support remediation retesting.
- Contribute to reconnaissance, attack-surface mapping, attack-path documentation, and controlled exploitation activities supporting red team exercises.
Requirements
- At least 2 years of hands-on professional experience in web application, API, and basic network or infrastructure security testing.
- Strong knowledge of authentication, session management, access control, input validation, and injection vulnerabilities.
- Experience with Burp Suite, Nmap, sqlmap, or similar tools, with the ability to test beyond automated scanning.
- Strong documentation and reporting skills, including clear articulation of security risk.
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- Foundational understanding of adversary simulation, reconnaissance, initial compromise, privilege escalation, lateral movement, and enterprise attack paths.
Nice to have
- Practical penetration testing certifications such as OSCP, OSWA, CWES, or BSCP.
- Interest in developing broader red team and offensive security capabilities.
Culture & Benefits
- 22 days of annual leave, increasing to 25 days based on length of service.
- Maternity, paternity, and parental leave.
- 100% private health insurance for employees and 50% family-member contribution from the date of hire.
- Annual bonus based on company and individual performance.
- Study assistance, including a master’s programme, and access to professional development training platforms.
- Fitness reimbursement, pension scheme, wellness programmes, healthcare services, vaccinations, eye care, and discounted events and classes.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Pentester (Cybersecurity)
Octobank
3 дня назад
Penetration Tester (Cybersecurity)
Iterasec
6 дней назад
Junior Penetration Tester
2 дня назад
Penetration Testing Lead (Cybersecurity)
92 701 - 119 966GBP
4 дня назад
Application Security Engineer - Vice President
2 дня назад
Advanced Intrusion Testing Lead (Cybersecurity)
92 701 - 119 966GBP