Penetration Tester
Indexed description
Penetration Tester
Hybrid (Romania)
Salary Dependant on Experience
ASAP
Responsibilities:
- Deliver penetration tests across web applications, APIs, internal networks, cloud platforms, and enterprise infrastructure.
- Perform manual security testing to identify vulnerabilities beyond automated scanning tools.
- Simulate real-world attack scenarios, including privilege escalation, Active Directory compromise, and lateral movement techniques.
- Assess cloud environments (AWS, Azure, and GCP) for security weaknesses, misconfigurations, and architectural risks.
- Review source code where appropriate to identify security issues early in the development lifecycle.
- Produce detailed technical reports that clearly explain findings, business impact, and remediation recommendations.
- Present assessment outcomes to engineering teams and senior stakeholders, providing practical advice on risk reduction.
- Support remediation activities through validation testing and follow-up assessments.
- Keep up to date with emerging vulnerabilities, attacker techniques, and developments within the offensive security community.
Technical Experience:
- At least 3 years of practical penetration testing or offensive security experience.
- Strong understanding of web application security, including OWASP Top 10 and API security best practices.
- Experience assessing internal infrastructure and exploiting common enterprise attack paths.
- Hands-on knowledge of Active Directory security, including Kerberoasting, NTLM relay, delegation abuse, ACL weaknesses, and privilege escalation techniques.
- Experience working within both Windows and Linux environments.
- Familiarity with TCP/IP, DNS, HTTP/S, Kerberos, NTLM, OAuth2, SSO, and modern authentication mechanisms.
- Proficiency with industry-standard offensive security tools such as Burp Suite, Nmap, Metasploit, BloodHound, CrackMapExec, and Impacket.
- Ability to automate or support testing activities using Bash, PowerShell, or Python.
- Strong report writing skills with the ability to clearly communicate technical findings and business risk.
Desirable Experience
- Certifications such as OSCP, PNPT, CRTO, or OSWE.
- Experience conducting Red Team exercises or adversary simulation engagements.
- Cloud penetration testing expertise across AWS, Azure, or GCP.
- Secure code review experience in languages such as Java, C#, Python, or JavaScript.
- Knowledge of threat modelling, attack path analysis, and defensive control bypass techniques within authorised environments.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search