Penetration Tester

OSEC LLC
United States
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Shift work
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Software System Penetration Testing Microsoft Azure Cloud Computing Perl (Programming Language) Internet Protocol Python (Programming Language) Routing Packet Analyzer
+8 more
Penetration Tools Ruby Security Software Tcpdump Wireshark Web Applications Scripting Golang

Job description

The Penetration Tester is responsible for working as part of the Assessment Team to conduct and participate in offensive and defensive security projects for OccamSec and its clients. This individual will work as part of a security team and report to an Assessment Team Lead., + Conduct security audits, network penetration tests, and web application, API and cloud assessments.

  • Draft security assessment reports that outline findings and provide a walkthrough of the assessment performed with evidence provided appropriately.
  • Use social engineering to identify improvement for security awareness and education.
  • Provide guidance and recommendation to clients on ways to fix or reduce security risks to their networks and products.
  • Operate as part of a team on larger, more complex projects with oversight from senior team members.
  • Operate independently on projects within defined-skill set, with oversight from a Project Manager.
  • Maintain proficiency in current security tools and skills.

Requirements

  • Candidates with at least 2-3 years of professional experience are preferred.
  • Proficient in working with AWS services like EC2, S3, KMS, RDS, or similar services on Azure & GCP, with a focus on implementing security best practices.
  • Skilled in conducting penetration tests for API, Mobile, Cloud, and Web Applications.
  • Familiarity with scripting languages such as Python, Perl, Go or Ruby.
  • Hands-on experience in building or developing Server or Application Technologies.
  • Utilized penetration tools effectively in various scenarios.
  • Applied expertise in replicating threat behaviors.
  • Proficient in using packet analyzer tools like Wireshark and tcpdump.
  • Sound understanding of IP network protocols, sub-netting, routing, switching, etc.
  • Extensive background in penetrating and exploiting secure networks and systems, staying updated with the latest security software packages, protocols, and computer technologies.
  • Excellent written and oral communication skills, with a proven track record in generating comprehensive reports and assessments.

Benefits & conditions

  • Flexible working hours;
  • Competitive health packages;
  • Life insurance;
  • 401k plan with company contributions
  • Maternity and parental leave;
  • On-the-job training opportunities; and
  • Paid, flexible vacation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Introduction to eBPF as a secure virtual machine

Ayesha Kaleem · WWC 2023

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

1:33 min

Case study on adopting Kubernetes and Golang effectively

Andrew Holway · LIVE

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all