- Company Name
- WorkNest
- Job Title
- Penetration Tester
- Job Description
-
Job Title: Penetration Tester
Role Summary: Conduct formal, comprehensive infrastructure penetration tests, produce detailed technical and non‑technical reports, support client pre‑engagement activities (scoping, proposal drafting), research and identify new vulnerabilities, manage large projects, mentor junior staff, deliver training, maintain QA processes, and contribute to marketing content.
Expectations: Deliver timely, high‑quality assessments of Windows and Linux environments (including Active Directory), network and application layers; apply OWASP, PTES, and MITRE ATT&CK frameworks; provide actionable remediation; collaborate across teams; maintain up‑to‑date skillset and certifications.
Key Responsibilities:
- Execute formal infrastructure and related penetration tests per industry standards.
- Draft comprehensive, concise reports in English.
- Conduct vulnerability assessments with clear remediation recommendations.
- Participate in scoping, proposal drafting, and client pre‑engagement interactions.
- Lead and mentor Graduate and Junior testers; develop in‑house training.
- Oversee large testing projects, ensuring adherence to deadlines.
- Research new vulnerabilities, manage responsible disclosure.
- Support QA process to meet SLA for high‑quality client reports.
- Contribute to marketing content (blogs, social media, articles).
- Perform any other duties aligned with role expertise.
Required Skills:
- Proven experience in infrastructure and application penetration testing.
- Deep knowledge of Windows/Linux, Active Directory, network principles, and operating systems.
- Proficiency with OWASP, PTES, and MITRE ATT&CK frameworks.
- Ability to program/scripting in preferred language.
- Advanced virtualisation knowledge.
- Excellent written and verbal communication, analytical, problem‑solving, and independent work orientation.
- Team collaboration, coaching, and mentoring abilities.
- Strong influencing and negotiation skills.
- Passion for security, continuous learning, lateral thinking, self‑motivation.
Required Education & Certifications:
- Security qualifications such as OSCP, CREST CRT, OSEP, or CCT‑INF.
- (Optional) Certifications in cloud (AWS/Azure) and red‑team tactics are advantageous.