Network penetration testing with tools such as Nessus, Nmap, MetasploitWeb application testing including advanced usage of Burp Suite ProTCP / IP networking and ability to troubleshoot connectivity issuesTest clients web and / or mobile applications and APIs to expose security weaknesses, being responsible for test quality and resolution of issues that may impede the test effort, for large or complex projectsContinuous learning by staying up to date on current testing tools and their applicability to a particular environmentProduce penetration testing reports based on testing resultsCollaborate with program team members to ensure testing runs smoothlyCommunicate effectively with the penetration testing teamQualifications :
- Bachelor s degree in business administration, cybersecurity, information technology, computer science or other related field or equivalent experience
- 2+ years of experience with TCP / IP networking and attacking endpoints at a network level
- 2+ years of experience with the Penetration Testing
- 2+ years of experience in an internal or external cybersecurity role, or similar (e.g., threat / penetration testing, ethical hacking, OWASP top 10, AppScan)
- Collaborative and able to effectively communicate with a team
- Desired Certifications : Offensive Security Certified Professional (OSCP), GPEN : GIAC Certified Penetration Tester, OffSec Web Assessor (OSWA), OffSec Web Expert (OSWE), API Security Certified Professional (ASCP), Certified API Security Analyst (CASA)
- Working knowledge of tools such as Burp Suite, Nessus, and the Kali Linux environment
- Experience with cloud penetration testing including K8S, AWS, and Azure
- Testing web applications, APIs, mobile applications, physical security, and social engineering (not all required, but multiple are expected)
- Experience with Dradis a plus and knowledge of vulnerabilities and exploits
Skills Required
Testing Tools, Linux, Owasp, Physical Security, Nessus, Nmap