-
Conduct web, network, mobile, and API penetration tests to identify vulnerabilities.
-
Support team assessments, simulating real-world attack scenarios.
-
Develop and execute custom exploits, scripts, and attack chains.
-
Conduct source code reviews for security weaknesses in applications.
-
Assess cloud security in AWS, Azure, and GCP, as well as containerized environments like Docker and Kubernetes.
-
Collaborate with blue teams, SOC analysts, and developers to remediate findings.
-
Write detailed technical reports and present findings to technical and non-technical stakeholders.
-
Stay updated on zero-day vulnerabilities, APT tactics, and emerging threats.
-
Participate in CTFs, security research, and bug bounty programs to refine skills.
-
1-2 years of hands-on penetration testing experience.
-
Proficiency in manual testing techniques beyond automated scanning.
-
Knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
-
Experience with Active Directory attacks, privilege escalation, and lateral movement.
-
Skilled in the use of tools like Burp Suite, Nessus, Metasploit, Kali Linux.
-
Familiarity with scripting in Python, PowerShell, Bash, or Ruby.
-
Excellent communication and interpersonal skills.

BrowserStack