Penetration Tester

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Penetration Tester conducting web, mobile, API, and network assessments for Velero’s cybersecurity and compliance consulting clients. Delivering actionable findings that strengthen security posture and regulatory readiness.

Responsibilities:

  • Conduct penetration tests on web applications, mobile applications, and APIs to identify vulnerabilities and potential exploits
  • Perform internal and external network penetration testing
  • Implement social engineering techniques, including phishing campaigns, to simulate real-world attacks and identify human-related security risks
  • Prepare detailed technical reports and provide actionable recommendations
  • Collaborate with internal teams and external clients on findings, mitigation strategies, and security best practices
  • Ensure compliance with GDPR, PCI-DSS, SOC 2, and other relevant security standards and regulations
  • Stay current on emerging threats, vulnerabilities, and security best practices

Requirements:

  • Proven experience (3+ years) in penetration testing across web apps, mobile apps, APIs, and network environments
  • Expertise in internal and external network penetration testing
  • Knowledge of common security vulnerabilities and attack vectors, including OWASP Top 10 and MITRE ATT&CK
  • Familiarity with Burp Suite, Nmap, Metasploit, Wireshark, Nessus, and other industry-standard tools
  • Experience with cloud environments such as AWS, Azure, and Google Cloud is a plus
  • Strong understanding of GDPR, PCI-DSS, SOC 2, and other regulatory frameworks
  • Excellent verbal and written communication skills, with the ability to present findings to technical and non-technical audiences
  • OSCP, CEH, GPEN, or similar certifications are preferred
  • Experience with mobile security frameworks and tools such as OWASP MSTG
  • Experience in API security testing, including OAuth and other common API security models
  • Proficiency in one or more programming/scripting languages such as Python, Bash, or JavaScript

Benefits:

  • Flexible, remote contract opportunity
  • Flexibility of remote work with a nearshore focus
  • Competitive compensation