- Company Name
- Venn Group
- Job Title
- Penetration Tester
- Job Description
-
Job Title: Penetration Tester
Role Summary: Deliver comprehensive vulnerability assessment and penetration testing services for cloud and on‑premise environments. Execute industry‑standard testing methodologies, leverage tools such as Burp Suite, Metasploit, and Nmap, and produce detailed technical reports with actionable remediation recommendations. Maintain awareness of emerging threats, attack techniques, and regulatory compliance requirements (GDPR, ISO27001, PCI DSS).
Expactations: • Active Security Clearance (SC) required. • CHECK Team Member qualification in CREST or CyberScheme. • Minimum 2–3 years of hands‑on penetration testing in cloud (AWS, Azure) and on‑premise environments.
Key Responsibilities:
- Conduct end‑to‑end penetration tests covering web, network, cloud, and wireless infrastructures.
- Identify, exploit, and document vulnerabilities using Burp Suite, Metasploit, Nmap, and other tools.
- Configure and analyze network devices, firewalls, IDS/IPS, and wireless technologies.
- Produce concise technical reports and executive summaries aligned with QA standards.
- Participate in IT health checks, risk assessments, and compliance audits (GDPR, ISO27001, PCI DSS).
- Manage project deliverables within defined policies, quality, commercial, and schedule parameters.
- Support commercial activities by preparing test scopes and proposals.
Required Skills:
- Proficiency with Windows and Linux (*NIX) operating systems.
- Cloud security expertise, including IAM, access controls, and configuration hardening for AWS and Azure.
- Advanced use of penetration testing tools: Burp Suite, Metasploit, Nmap, etc.
- Understanding of security standards and regulatory frameworks (GDPR, ISO27001, PCI DSS).
- Strong written and verbal communication for report writing and stakeholder engagement.
- Self‑management, deadline orientation, and commercial awareness.
Required Education & Certifications:
- CREST or other team member certification (mandatory).
- CyberScheme or equivalent qualification (preferred).
- Relevant degree in Computer Science, Cyber Security, or related field (optional if certifications are demonstrably proven).