Назад
Company hidden
обновлено 20 дней назад

Penetration Testing Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Philippines
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Penetration Testing Analyst (Cybersecurity): Performing hands-on web, API, mobile, and infrastructure penetration testing with an accent on manual vulnerability discovery, exploitation, risk assessment, and remediation reporting. Focus on researching attack techniques, mapping attack paths, validating fixes, and supporting foundational Red Team activities including reconnaissance, initial access, privilege escalation, and lateral movement awareness.

Location: Taguig City, National Capital Region (Manila), Philippines

Company

hirify.global helps clients achieve lifetime financial security and live healthier lives through financial and insurance-related services.

What you will do

  • Perform web, API, mobile, and infrastructure penetration testing across enterprise applications.
  • Identify, exploit, and validate vulnerabilities through manual testing and industry tools.
  • Conduct testing according to OWASP and established security methodologies.
  • Prepare structured reports covering root causes, business impact, risk ratings, and remediation recommendations.
  • Research vulnerabilities, exploits, and attack techniques, and perform retesting to validate remediation.
  • Support reconnaissance, attack-surface mapping, attack-path documentation, and foundational Red Team activities.

Requirements

  • At least 2 years of hands-on experience in web application security testing, API security testing, and basic network or infrastructure testing.
  • Strong understanding of authentication, session management, access control, input validation, and injection vulnerabilities.
  • Experience with Burp Suite, Nmap, sqlmap, or similar security testing tools.
  • Ability to perform manual testing beyond automated scanning and clearly document security risks.
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Basic understanding of adversary simulation, reconnaissance, initial compromise, privilege escalation, lateral movement, and enterprise attack paths.

Nice to have

  • OSCP, OSWA, CISSP, CompTIA, or similar certification.
  • Interest in developing broader Red Team and offensive security capabilities.

Culture & Benefits

  • Collaborative environment with colleagues who share technical knowledge.
  • Support from leaders focused on professional growth and development.
  • Opportunities to contribute to security work that protects clients and communities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →