CST Associate Penetration Tester

3 months ago


Hyderabad, India Claranet Full time

Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil.

We are recognized as a major actor for Cloud Services in Europe.


About Us

About Claranet

Founded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries.


At Claranet, we’re experienced in implementing progressive technology solutions which help our customers solve their epic business challenges. We’re committed to understanding their problems, delivering answers quickly, and making a lasting impact to their business.

We are agile, focused and experienced in business modernisation. Our approach helps customers make genuine, significant shifts in their business strategy, to deliver financial savings, boost innovation, and create a resilient business. We continually invest in our people and the latest technologies, so our customers get peace of mind knowing that they have access to the best talent and services.


In the UK we have over 500 staff working in London, Gloucester, Warrington, Bristol, and Leeds, or as homeworkers.


About The Role


The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack surface for new vulnerabilities, changes in the scope of the attack surface, and proactively inform customers of discovered issues along with recommended remediation; with the overall aim of reducing the lifetime of each vulnerability. Manual testing includes identification of issues which automation alone could not identify, exploitation of all issues, often chaining multiple findings together in order to determine the true impact of vulnerabilities for the customer.

  • Manual identification and exploitation of vulnerabilities.
  • Manual verification and exploitation of scanner findings.
  • Detailed analysis of issues identified and exposure for the customer including proof of concept, reproduction steps, and recommended remediation.
  • Communication of findings to the customer in a detailed, accurate and manageable manner both orally and through written vulnerability/scope notifications and periodic summaries.
  • Continual professional development to maintain and develop knowledge and technical competencies.
  • Maintain professional technical qualifications to demonstrate competency to our clients.
  • Undertaking projects and support tasks as appropriate to the role.


Progression:

During mentoring and experience progression, the Associate Penetration Tester will be tasked with

  • Pre-engagement activities including scoping of assessments and statements of work and determining customer requirements and restrictions.
  • On boarding customers into the service including configuration of continual scanning and liaising with customer to resolve issues which may reduce the effectiveness of scanning.
  • Monitoring of the customers’ external perimeter for changes, and proactive discovery of new targets to include within the customer’s scope.


About You

Essential:

  • Excellent written and spoken English including presentation, structure, spelling, and grammar. Along with experience conveying technical information in an accessible manner.
  • Core computing skills including but not limited to:
  • Networking fundamentals – understanding of OSI Model, TCP/IP, HTTP, DNS, SMB, SMTP and relevant tools.
  • Microsoft Windows and Office proficiency along with proficiency in one or more Linux distributions.
  • Good knowledge of web application technologies and security assessment including but not limited to:
  • REST APIs, XML and JSON formats.
  • Vulnerability identification and exploitation (not limited to OWASP Top 10).
  • Experience with common assessment tools such as MITM proxies (e.g. Burp Suite Pro and SQLMap).
  • General knowledge of internal and external infrastructure technologies and security assessment including but not limited to:
  • Identification and exploitation of misconfigurations or known vulnerabilities in common enterprise infrastructure and services (Windows Domains, Linux servers, virtualisation, databases, switches/routers, etc).
  • Knowledge of a scripting language such as Python (preferred), Ruby, PowerShell, or Bash, for the development of new, or editing existing, tools.
  • Evidence of rapidly and confidently gaining and knowledge of emerging technologies, vulnerabilities, and penetration testing tools and techniques.
  • Excellent time management including setting priorities and goals to complete assigned and arising tasks.


Desirable:

  • CPSA - CREST Practitioner Security Analyst (or above)
  • Public speaking experience
  • A related Bachelor’s degree.
  • Experience with live bug bounties, particularly where automation has been implemented.
  • Knowledge of Open Source Intelligence gathering techniques. Including but not limited to use of Google dorks, DNS, domain registration, certificate transparency, and other public sources of information.


Position Summary


The primary function of the Associate Penetration Tester in the CST team is to manually verify the findings of the automated scanners and assist the team to achieve the delivery goals. The Associate Penetration Tester will be properly mentored in order to support the Penetration Testers on pre-engagement activities including scoping, statements of work, working with customers to determine their testing requirements and restrictions, and on boarding customers into the service, as well as on manual testing



  • Hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil. We are recognized as a major actor for Cloud Services in Europe. About Us About Claranet Founded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb...


  • Hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil. We are recognized as a major actor for Cloud Services in Europe. About Us About Claranet Founded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb...


  • Hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil.We are recognized as a major actor for Cloud Services in Europe.About UsAbout ClaranetFounded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb moment to...


  • hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil. We are recognized as a major actor for Cloud Services in Europe. About Us About Claranet Founded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb moment...


  • hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil.We are recognized as a major actor for Cloud Services in Europe.About UsAbout ClaranetFounded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb moment to...


  • hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil. We are recognized as a major actor for Cloud Services in Europe. About Us About Claranet Founded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb...


  • Hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil. We are recognized as a major actor for Cloud Services in Europe. About Us About Claranet Founded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb...


  • Hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil.We are recognized as a major actor for Cloud Services in Europe.About UsAbout ClaranetFounded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb moment to...


  • hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil.We are recognized as a major actor for Cloud Services in Europe.About UsAbout ClaranetFounded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb moment to...


  • Hyderabad, India Claranet Full time

    Claranet provides network, hosting, managed application services and digital transformation in the UK, France, Germany, Netherlands, Portugal, Spain, Italy and Brazil. We are recognized as a major actor for Cloud Services in Europe. About Us About Claranet Founded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light...


  • Hyderabad, Telangana, India Claranet Full time

    About the RoleThe CST team at Claranet is seeking a skilled Associate Penetration Tester to join our team of experts in continuous security testing.This role is perfect for someone with a passion for security and a keen eye for detail, who is looking to develop their skills in manual penetration testing.As an Associate Penetration Tester, you will work...


  • Hyderabad, India Claranet Full time

    **About The Role**: The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack...

  • Penetration Tester

    5 months ago


    Hyderabad, Telangana, India Experian Full time

    Full-time Employee Status: Regular Role Type: Hybrid Department: Information Technology & Systems Schedule: Full Time **Company Description**: Experian is the world’s leading global information services company. During life’s big moments — from buying a home or a car to sending a child to college to growing a business by connecting with new...

  • Penetration Tester

    5 months ago


    Hyderabad, Telangana, India Experian Full time

    **Company Description** Experian unlocks the power of data to create opportunities for consumers, businesses and society. During life’s big moments - from buying a home or car, to sending a child to college, to growing a business exponentially by connecting it with new customers - we empower consumers and our clients to manage data with confidence so they...

  • Penetration Tester

    5 months ago


    Nanakramguda, Hyderabad, Telangana, India VATINS SYSTEMS PVT LIMITED Full time

    **Job Description for Penetration Tester** **Position**: Penetration Tester **Location**: Hyderabad, India We have an opening for a Penetration Tester to join our team and help our development initiatives. This is a great opportunity for aspiring Penetration Tester’s to obtain practical experience and make a meaningful...

  • Penetration Tester

    2 weeks ago


    hyderabad, India Castellum Labs Full time

    Castellum Labs is a next-generation cybersecurity technology venture based in Hyderabad, India, with global set of customer base and global ambitions. Our vision is to change the cybersecurity value model in the industry by using custom designed in-house technologies for service delivery.Our primary focus areas in cybersecurity are DevSecOps, Application...

  • Penetration Tester

    5 days ago


    Hyderabad, India Castellum Labs Full time

    Castellum Labs is a next-generation cybersecurity technology venture based in Hyderabad, India, with global set of customer base and global ambitions. Our vision is to change the cybersecurity value model in the industry by using custom designed in-house technologies for service delivery.Our primary focus areas in cybersecurity are DevSecOps, Application...

  • Penetration tester

    2 weeks ago


    Hyderabad, India Castellum Labs Full time

    Castellum Labs is a next-generation cybersecurity technology venture based in Hyderabad, India, with global set of customer base and global ambitions. Our vision is to change the cybersecurity value model in the industry by using custom designed in-house technologies for service delivery. Our primary focus areas in cybersecurity are Dev Sec Ops,...

  • Penetration Tester

    2 weeks ago


    Hyderabad, India Castellum Labs Full time

    Castellum Labs is a next-generation cybersecurity technology venture based in Hyderabad, India, with global set of customer base and global ambitions. Our vision is to change the cybersecurity value model in the industry by using custom designed in-house technologies for service delivery. Our primary focus areas in cybersecurity are DevSecOps, Application...

  • Penetration Tester

    2 days ago


    hyderabad, India Castellum Labs Full time

    Castellum Labs is a next-generation cybersecurity technology venture based in Hyderabad, India, with global set of customer base and global ambitions. Our vision is to change the cybersecurity value model in the industry by using custom designed in-house technologies for service delivery.Our primary focus areas in cybersecurity are DevSecOps, Application...