Назад
Company hidden
5 дней назад

Penetration Testing Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Philippines
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Penetration Testing Analyst (Cybersecurity): Performing hands-on security testing of applications, infrastructure, and systems with an accent on web, API, and mobile penetration testing. Focus on identifying vulnerabilities, validating security gaps, and contributing to adversary simulation exercises.

Location: Onsite in Taguig City, National Capital Region (Manila), Philippines

Company

A global financial services organization dedicated to helping clients achieve lifetime financial security and live healthier lives.

What you will do

  • Perform web, API, mobile, and infrastructure penetration testing across enterprise applications.
  • Identify, exploit, and validate security vulnerabilities using manual testing techniques and industry tools.
  • Conduct testing in alignment with established methodologies and security frameworks such as OWASP.
  • Produce structured reports detailing vulnerabilities, root causes, business impact, and practical remediation recommendations.
  • Research new vulnerabilities and attack techniques to enhance testing coverage and support re-testing activities.
  • Support Red Team activities, including reconnaissance, attack surface mapping, and controlled exploitation activities.

Requirements

  • 2+ years of hands-on experience in web application (OWASP Top 10), API, and basic network/infrastructure security testing.
  • Strong understanding of authentication, session management, access control flaws, and injection vulnerabilities.
  • Proficiency with tools such as Burp Suite, Nmap, and sqlmap.
  • Ability to perform manual testing beyond automated scanning.
  • Strong documentation and reporting skills with a focus on clear risk articulation.
  • Bachelor's degree in Computer Science, Information Security, or a related field.

Nice to have

  • Foundational understanding of adversary simulation concepts, attack lifecycles, and reconnaissance techniques.
  • Awareness of privilege escalation and lateral movement concepts in enterprise environments.
  • Relevant certifications such as OSCP, OSWA, CISSP, or CompTIA.

Culture & Benefits

  • Work with a dynamic team of experts in an environment that encourages growth and achievement.
  • Supportive leadership focused on helping employees reach their full potential.
  • Opportunity to make a meaningful difference in the lives of clients globally.
  • Collaborative culture based on values of caring, authenticity, and impact.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →