Job Summary:
We are excited to share a highly rewarding and hands-on opportunity for a skilled and experienced Senior Penetration Tester to join our Technical Consulting Team. As part of our team, you will be responsible for conducting penetration tests, vulnerability assessments, and reporting findings to help detect legacy and bleeding-edge security vulnerabilities in enterprise environments.
You should have a firm grasp of networking, system administration, and web application security. The ability to think outside the box and go beyond conventional attack paths and exploits is highly valued by our team.
As part of this team, the successful applicant will have oversight and responsibility over assigned Penetration Testing engagements, Web Application Penetration Tests, SilverSky's Penetration Testing as a Service (PTaaS) offering, as well as SilverSky's Continuous Validation and Red Teaming services.
This will be a remote position for the ideal candidate.
Duties/Responsibilities:
1. Scope and perform a variety of penetration tests, including but not limited to Infrastructure (internal and external), Web Applications, APIs, Mobile, Wireless and Cloud.
2. Keep cybersecurity training and knowledge current by monitoring the latest security threats and vulnerabilities.
3. Write clear and concise penetration testing reports detailing findings and recommendations for remediation of identified vulnerabilities.
4. Coordinate and lead client kick-off and discovery sessions to answer questions from prospects and clients.
5. Work collaboratively and independently with teammates to provide professional services to our clients.
6. Use offensive security expertise to research relevant tactics, techniques, and procedures for assessing and validating weaknesses in various infrastructure and technologies including cloud technologies.
7. Develop scripts to automate repetitive actions of penetration tests.
8. Identify and provide improvements on existing services, including continuous improvement of existing methodologies, tools and reports.
9. Serve as a mentor to other Penetration testers and support them in their work.
10. Assist in pre-sales efforts as a penetration testing subject-matter expert.
Required Skills/Abilities:
1. Strong knowledge of various operating systems and networks, especially experience with Linux, Windows, and Active Directory.
2. Strong experience with web application pen testing methodologies, such as OWASP's WSTG.
3. Strong experience with web application pen testing toolsets, such as Burp Suite.
4. Strong experience in identifying and exploiting web application vulnerabilities.
5. Experience with penetration testing tools and frameworks such as Metasploit, Nmap, and Nessus.
6. Strong communication and report-writing skills in English.
Education and Experience:
1. Minimum of 3+ years' experience as a penetration tester. Web application testing and API testing experience is desirable.
2. Relevant security qualifications (such as OSCP, CREST CRT, PNPT).
3. Web application qualifications is desirable (such as eWPT, OSWA/OSWE, CMWAPT, CREST CWAT, eWPTx).
#J-18808-Ljbffr