- Company Name
- Computacenter
- Job Title
- Senior Penetration Tester
- Job Description
-
**Job Title:** Senior Penetration Tester
**Role Summary:**
Seasoned security professional responsible for planning, executing, and reporting comprehensive penetration tests across infrastructure, applications, cloud, and social engineering vectors. Works collaboratively with development, operations, and security teams to improve resilience and guide remediation, while contributing to tool development, threat modeling, and security awareness initiatives.
**Expectations:**
- Minimum 5 years full‑time penetration testing experience, including Red/Purple Team engagements.
- Proven ability to identify, exploit, and communicate high‑impact vulnerabilities.
- Commitment to continuous learning and staying current with emerging threats and techniques.
- Strong collaboration and communication skills across technical and non‑technical audiences.
**Key Responsibilities:**
- Perform internal/external network, web, mobile, API, cloud, and social engineering penetration tests.
- Conduct vulnerability research, exploitation, and detailed risk analysis.
- Participate in Red/Blue/Purple Team exercises to enhance organizational cyber resilience.
- Produce professional reports with executive summaries, technical findings, risk ratings, and remediation recommendations.
- Advise development, operations, and security teams on mitigation strategies.
- Evaluate, customize, and develop penetration testing tools and methodologies.
- Contribute to security awareness training and threat‑modeling sessions.
- Execute ad‑hoc security assessments and provide expert guidance as required.
**Required Skills:**
- Deep knowledge of infrastructure, Active Directory, network devices, and cloud security (Azure/Entra ID).
- Expertise in web application security testing and exploitation techniques.
- Experience with Red Team operations, physical security, and social engineering.
- Ability to create or adapt custom tooling; proficiency in at least one major programming language.
- Strong analytical, problem‑solving, and documentation skills.
- (Optional) Experience with IoT, mobile security, public research/blogs, open‑source contributions.
**Required Education & Certifications:**
- Relevant certifications (e.g., OSCP, OSEP, CRTO, SANS GRTP, SANS GXPEN, CSTL, or equivalents).
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).