CST - Associate Penetration Tester
4 days ago
Vacancy Name
CST - Associate Penetration Tester
Req Number
VN290
Employment Type
Full-Time
Location
India
Position Summary
About Claranet
Founded at the beginning of the bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries.
At Claranet, we're experienced in implementing progressive technology solutions which help our customers solve their epic business challenges. We're committed to understanding their problems, delivering answers quickly, and making a lasting impact to their business.
We are agile, focused and experienced in business modernisation. Our approach helps customers make genuine, significant shifts in their business strategy, to deliver financial savings, boost innovation, and create a resilient business. We continually invest in our people and the latest technologies, so our customers get peace of mind knowing that they have access to the best talent and services.
In the UK we have over 500 staff working in London, Gloucester, Warrington, Leeds or as homeworkers.
Working For Claranet
Here at Claranet we pride ourselves on going the extra mile for and with our employees (yes, we really mean with). We offer an extensive benefits package that you can tailor to your needs, inclusive of a matching contribution pension scheme, healthcare, insurance, dental, discounted gyms and app supported benefit access.
But what we think makes us different is 'Team Claranet,' our dedicated internal part of the business that supports you with matters close to your heart. We proudly support local charities in each of our office locations, support employees with paid charity leave, organise key charity fundraising event per year and have a dedicated committee responsible for supporting employee's fundraising efforts.
Claranet are one of the 10 founding members of TC4RE (Technology Community for Racial Equality.) Being a part of a group of leading UK technology organisations, we are dedicated to building a more diverse and inclusive workforce.
Our Vision
Our vision is to become the most trusted technology solutions partner; renowned for being the best and brightest, having lasting impact with our customers and delivering exceptional returns to our stakeholders.
Position Summary
Claranet Cyber Security is a world class business unit within Claranet, designed to give customers access to market-leading information security expertise and services spanning; penetration testing, compliance consulting, training and managed services.
The primary function of the Penetration Tester in the CST team is to continually review the customers' defined scope for vulnerabilities, identify additional targets that should be included in the scope, and report these to the client in a timely, accurate, and comprehensive manner. The Penetration Tester is also responsible for pre-engagement activities including scoping, statements of work, working with customers to determine their testing requirements and restrictions, on boarding customers into the service and contribute to the service improvement and further development.
To provide the best services to our clients, we need the best people working with us. With outstanding support from the business, all of our penetration testers will gain the experience needed to become the best they can be.
Our team is growing, and we need inspiring people to join us at all levels and help us to continue building a world leading cyber security operation whilst benefiting from a truly unique opportunity to fulfil their potential.
Duties and Responsibilities
Essential Roles & Responsibilities
The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer's external attack surface for new vulnerabilities, changes in the scope of the attack surface, and proactively inform customers of discovered issues along with recommended remediation; with the overall aim of reducing the lifetime of each vulnerability. Manual testing includes identification of issues which automation alone could not identify, exploitation of all issues, often chaining multiple findings together in order to determine the true impact of vulnerabilities for the customer.
Key Responsibilities:
- Manual identification and exploitation of vulnerabilities
- Manual verification and exploitation of scanner findings
- Detailed analysis of issues identified and exposure for the customer including proof of concept, reproduction steps, and recommended remediation
- Communication of findings to the customer in a detailed, accurate and manageable manner both orally and through written vulnerability/scope notifications and periodic summaries
- Continual professional development to maintain and develop knowledge and technical competencies
- Maintain professional technical qualifications to demonstrate competency to our clients
- Undertaking projects and support tasks as appropriate to the role
Progression:
During mentoring and experience progression, the Associate Penetration Tester will be tasked with:
- Pre-engagement activities including scoping of assessments and statements of work and determining customer requirements and restrictions
- Onboarding customers into the service including configuration of continual scanning and liaising with customer to resolve issues which may reduce the effectiveness of scanning
- Monitoring of the customers' external perimeter for changes, and proactive discovery of new targets to include within the customer's scope
Position Specifications
Essential Technical
Core computing skills including but not limited to:
- Networking fundamentals – understanding of OSI Model, TCP/IP, HTTP, DNS, SMB, SMTP and relevant tools
- Microsoft Windows and Office proficiency along with proficiency in one or more Linux distributions
Good knowledge of web application technologies and security assessment including but not limited to:
- REST APIs, SOAP APIs, XML and JSON formats
- Vulnerability identification and exploitation (not limited to OWASP Top 10)
- Experience with common assessment tools such as MITM proxies (e.g. Burp Suite Pro) and SQLMap
- Good knowledge of internal and external infrastructure technologies and security assessment including but not limited to:
Identification and exploitation of misconfigurations or known vulnerabilities in common enterprise infrastructure and services (Windows Domains, Linux servers, virtualisation, databases, switches/routers, etc)
- Windows and Linux Sandbox/Desktop Breakout
Knowledge of a scripting language such as Python (preferred), Ruby, PowerShell, or Bash, for the development of new, or editing existing, tools
Essential General
- Must be self-motivated and able to work in an independent manner as well as part of a team
- Excellent written and oral communications skills
- Positive, collaborative and enthusiastic
- Appetite to shadow, train and develop to improve capabilities into all areas of security testing
In Addition, The Following Are Highly Desirable:
- CPSA - CREST Practitioner Security Analyst (or above)
- Public speaking experience
- A related Bachelor's degree
- Experience with live bug bounties, particularly where automation has been implemented
- Knowledge of Open Source Intelligence gathering techniques. Including but not limited to use of Google dorks, DNS, domain registration, certificate transparency, and other public sources of information
Salary
Competitive
-
Penetration Tester
5 days ago
India CIEL HR Full timeJob Summary **ROLE**:.penetration tester **Experience**: 3 - 7 Years **Location**: Chennai Work Location - DLF, Chennai - Work from Office Alternative saturday working **Security Test Engineer**: Understand the non-functional requirements from business. Experience in Analyzing and identifying the vulnerabilities manually. Experience in Web Application...
-
Penetration Tester
4 weeks ago
Ahmedabad, Gujarat, India, Gujarat Asite Full timePenetration Testers - Junior and Senior/LeadLocation:In Office, Ahmedabad, Gujarat, India (not remote)Full-timeSalary: Up to ₹12.5L (1,250,000) INR per year for Senior/LeadMust undergo background check and security clearanceCandidates must already have the right to work and live in IndiaAbout AsiteAsite’s vision is to connect people and help the world...
-
Senior penetration tester
3 weeks ago
India Vista Applied Solutions Group Inc Full timeJob Summary: Client is looking for Senior Pen Tester and this is remote position from India. Experience: 5+ years of relevant experience in Security and Penetration Testing OSCP Certification - Industry-standard credential demonstrating practical penetration testing skills Manual Testing Expertise - Ability to perform thorough hands-on security...
-
Penetration Tester
1 week ago
Hyderabad, Telangana, India, Telangana NTT DATA, Inc. Full timeYour day at NTT DATA The Penetration Tester is a seasoned subject matter expert, responsible for assessing and evaluating the security posture of the company's information systems, networks, applications and infrastructure. This role involves conducting rigorous penetration testing and ethical hacking activities to identify vulnerabilities and potential...
-
Penetration Tester
3 weeks ago
Bengaluru, Karnataka, India, Karnataka ACL Digital Full timeJob Purpose As a Senior Penetration Tester, your primary role is to assess and enhance the security of our information systems, networks, and applications through comprehensive penetration testing and vulnerability assessments. You will work closely with our internal product teams to identify weaknesses in their systems and provide actionable recommendations...
-
Senior Penetration Tester
4 weeks ago
India Vista Applied Solutions Group Inc Full timeJob Summary:Client is looking for Senior PenTester and this is remote position from India.Experience:5+ years of relevant experience in Security and Penetration TestingOSCP Certification - Industry-standard credential demonstrating practical penetration testing skills Manual Testing Expertise - Ability to perform thorough hands-on security assessments beyond...
-
Senior Penetration Tester
2 weeks ago
Bangalore - Manyata Tech Park Road, India Commonwealth Bank of Australia Full time ₹ 8,00,000 - ₹ 24,00,000 per yearSenior Penetration Tester Organization: At CommBank, we never lose sight of the role we play in other people's financial wellbeing. Our focus is to help people and businesses move forward to progress. To make the right financial decisions and achieve their dreams, targets, and aspirations. Regardless of where you work within our organisation, your...
-
Senior Penetration Tester
4 weeks ago
India Vista Applied Solutions Group Inc Full timeJob Summary: Client is looking for Senior PenTester and this is remote position from India. Experience: 5+ years of relevant experience in Security and Penetration Testing OSCP Certification - Industry-standard credential demonstrating practical penetration testing skills Manual Testing Expertise - Ability to perform thorough hands-on security assessments...
-
Senior Penetration Tester
3 weeks ago
Bengaluru, Karnataka, India, Karnataka ACL Digital Full timeBachelor’s degree in computer science/engineering, information security, or a related field.Proven experience in penetration testing, vulnerability assessment, and security testing with a minimum of 8 years in a similar role.Proven track record of conducting successful penetration tests for a variety of organizations and industries.Industry-recognized...
-
Senior Penetration Tester
4 weeks ago
india, IN Vista Applied Solutions Group Inc Full timeJob Summary:Client is looking for Senior PenTester and this is remote position from India.Experience:5+ years of relevant experience in Security and Penetration TestingOSCP Certification - Industry-standard credential demonstrating practical penetration testing skills Manual Testing Expertise - Ability to perform thorough hands-on security assessments beyond...