
Penetration Tester
2 weeks ago
**About The Role**:
The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack surface for new vulnerabilities, changes in the scope of the attack surface, and proactively inform customers of discovered issues along with recommended remediation; with the overall aim of reducing the lifetime of each vulnerability. Manual testing includes identification of issues which automation alone could not identify, exploitation of all issues, often chaining multiple findings together in order to determine the true impact of vulnerabilities for the customer.
- Pre-engagement activities including scoping of assessments and statements of work and determining customer requirements and restrictions.
- On boarding customers into the service including configuration of continual scanning and liaising with customer to resolve issues which may reduce the effectiveness of scanning.
- Monitoring of the customers’ external perimeter for changes, and proactive discovery of new targets to include within the customer’s scope.
- Manual identification and exploitation of vulnerabilities.
- Manual verification and exploitation of scanner findings.
- Detailed analysis of issues identified and exposure for the customer including proof of concept, reproduction steps, and recommended remediation.
- Communication of findings to the customer in a detailed, accurate and manageable manner both orally and through written vulnerability/scope notifications and periodic summaries.
- Assisting in the continual development of the team and service through research and development activities. This includes the development of in-house tools the implementation of tools released to the community, and design and documentation of new and existing internal systems and processes.
- Continual professional development to maintain and develop knowledge and technical competencies.
- Maintain professional technical qualifications to demonstrate competency to our clients.
- Contributing to the writing and publishing of whitepapers and advisories.
- Undertaking projects and support tasks as appropriate to the role.
**About You**:
**Essential**
**Technical**:
- Core computing skills including but not limited to:
- Networking fundamentals - understanding of OSI Model, TCP/IP, HTTP, DNS, SMB, SMTP and relevant tools.
- Microsoft Windows and Office proficiency along with proficiency in one or more Linux distributions.
- REST APIs, SOAP APIs, XML and JSON formats.
- Vulnerability identification and exploitation (not limited to OWASP Top 10).
- Experience with common assessment tools such as MITM proxies (e.g. Burp Suite Pro) and SQLMap.
- Good knowledge of internal and external infrastructure technologies and security assessment including but not limited to:
- Identification and exploitation of misconfigurations or known vulnerabilities in common enterprise infrastructure and services (Windows Domains, Linux servers, virtualisation, databases, switches/routers, etc).
- Knowledge of a scripting language such as Python (preferred), Ruby, PowerShell, or Bash, for the development of new, or editing existing, tools.
**Essential Experience**:
- Providing remediation advice
- Producing accurate technical reports
- Working under pressure of deadlines and structuring workload accordingly
- Problem-solving, helping others to understand complex ideas
**Essential General**:
- Client facing, able to confidently and professionally represent the company
- Must be self-motivated and able to work in an independent manner as well as part of a team
- Excellent written and oral communications skills
- Positive, collaborative and enthusiastic
- Appetite to shadow, train and develop to improve capabilities into all areas of security testing
**In addition, the following are highly desirable**:
- CEH, OSCP, OSWE or equivalent reputable information security certifications
- Familiarity with testing cloud environments
- Public speaking experience
**About Us**:
**About Claranet**
At Claranet, we’re experienced in implementing progressive technology solutions which help our customers solve their epic business challenges. We’re committed to understanding their problems, delivering answers quickly, and making a lasting impact to their business.
We are agile, focused and experienced in business modernisation. Our approach helps customers make genuine, significant shifts in their business strategy, to deliver financial savings, boost innovation, and create a resilient business. We continually invest in our people and the latest technologies, so our customers get peace of mind knowing that they have access to the best talent and services.
In the UK we have over 500 staff working in London, Gloucester, Warrin
-
Penetration Tester
19 hours ago
Remote, India Agylex-Sprinx Global Full time**Location**:UAE (Relocation Needed) **Duration**: 12 months + 12 months **Position Overview**: **Key Responsibilities**: - Collaborate closely with interdisciplinary teams to analyze and interpret security assessment outcomes, furnishing actionable recommendations for remediation. - Remain abreast of the latest cybersecurity trends, tools, and...
-
Vapt Tester-remote
19 hours ago
Remote, India TeamPlus Staffing Solution Pvt Ltd Full timeThe Penetration tester must have CREST accreditation status in order to qualify for the Project. Penetration tester must hold minimum 2 of the following qualifications or equivalent. Offensive Security Certified Professional (OSCP) Certified Information Systems Security Professional (CISSP) Offensive Security Certified Wireless Professional (OSWP) CREST...
-
Cyber Security Tester
19 hours ago
Remote, India Rigelsoft Technologies Full time**Cyber Security - Penetration Tester** Security roles: - Penetration Testers There are multiple headcounts across different levels for this role. If you are a penetration tester looking for your next penetration testing or just cyber security roles in general, feel free to get in touch for a confidential discussion regarding your next career...
-
Penetration Tester
2 weeks ago
Remote, India NexusCrypt Full time**About NexusCrypt** We're not your typical security company. We're a team of enthusiastic cybersecurity professionals dedicated to empowering businesses to navigate the ever-changing threat landscape. We achieve this by offering a comprehensive suite of penetration testing services, essentially acting as ethical hackers to identify and fix vulnerabilities...
-
Penetration Tester
19 hours ago
Remote, India Claranet Full time**About The Role**: **Role** The primary function of the Security Analyst in the CST team is to continually review the customers’ defined scope for vulnerabilities, identify additional targets that should be included in the scope, and report these to the client in a timely, accurate, and comprehensive manner. The Security Analyst is also responsible for...
-
Penetration Tester
1 week ago
Remote, India MegThink Full timeKey Responsibilities: Perform vulnerability assessments, exploit weaknesses, and provide detailed security analysis. Analyze security breaches and identify attack vectors and vulnerabilities. Develop, execute, and document test plans and methodologies for comprehensive security testing. Collaborate with IT teams to implement remediation strategies and...
-
Mobile Application Penetration Tester
4 hours ago
Remote, India Zimperium Full time ₹ 12,00,000 - ₹ 36,00,000 per yearZimperium is an industry leader in enterprise mobile security, being the first and only company to provide a complete mobile threat defense system that offers real-time, on device world-class protection against both known and unknown next generation of advanced mobile cyberattacks and malware.Our MTD and award-winning machine learning-based engine protects...
-
Security Tester Intern
4 days ago
Remote, India BeSpoke AI Stylist Private Limited Full time**Key Responsibilities**: - Support in **penetration testing** and simulate attacks to test system resilience. - Help in performing **vulnerability assessments** and documenting findings. - Work closely with developers to suggest **fixes and improvements**. - Ensure **data privacy and protection standards** are being followed. - Stay updated with the latest...
-
Security Tester Intern
1 week ago
Remote, India BeSpoke AI Stylist Private Limited Full time ₹ 3,60,000 - ₹ 5,40,000 per yearKey Responsibilities:Assist in identifying and reporting security vulnerabilities in web & mobile applications.Support in penetration testing and simulate attacks to test system resilience.Help in performing vulnerability assessments and documenting findings.Work closely with developers to suggest fixes and improvements.Ensure data privacy and protection...
-
Tester
2 weeks ago
Remote, India Blupace Full timeAbout the job Why join us? Blupace is a world-class IT development company that strives to improve its processes constantly. The company has been in business since 2008 and employs over 160+ people in more than 4 countries. Blupace provides innovative software solutions for businesses of all sizes, with a focus on Web & Mob Applications, e-commerce...