03 / 07
Senior Penetration Tester
Lead complex penetration tests across web applications, infrastructure, cloud environments and other applications. Identify non-obvious vulnerabilities, develop proof-of-concept exploits and produce reports that support effective remediation.
What you’ll do
- Scope and lead black-box and white-box penetration tests covering web applications, APIs, networks, cloud environments and mobile applications.
- Develop custom exploits, scripts and tools to bypass controls and demonstrate concrete impact.
- Test manually and in depth beyond automated scanners, combining individual findings into realistic attack paths and business risk.
- Write precise, reproducible reports and guide clients through remediation.
- Help shape testing methodology, tooling and quality standards across the team.
- Mentor junior testers and review their work.
What you bring
- At least four years of penetration-testing or offensive-security experience, including experience leading engagements.
- Strong across the OWASP Top 10, network and Active Directory attacks, and at least one cloud (Azure/AWS/GCP).
- Fluency in at least one scripting language, such as Python, Bash or Ruby, for custom tooling and automation.
- Practical experience with Burp Suite, Nmap, Metasploit, BloodHound and comparable tools.
- OSCP or equivalent skills, together with strong technical writing in English.
Additional advantages
- Source-code review
- OT/ICS, mobile or thick-client testing
- Public Burp/Ghidra extensions
- CVEs or CTF placings