Job Description
We are seeking a highly skilled and proactive Penetration Testing Specialist to join our Risk Advisory & IT Audit team. In this role, you will play a critical part in assessing and strengthening our clients’ cybersecurity posture. You will simulate real-world cyberattacks across systems, networks, and applications to identify security vulnerabilities before they can be exploited, translating technical findings into actionable business insights for client leadership.
Key Responsibilities:
- Penetration Testing & Assessments: Execute comprehensive internal/external penetration tests across web applications, mobile apps, network infrastructure, and cloud environments for clients.
- Vulnerability Management: Perform routine vulnerability scans, validate identified risks, and evaluate their potential operational and business impact.
- Report Writing & Consultation: Draft clear, detailed technical and executive reports outlining vulnerabilities, risk levels, and prioritized remediation strategies.
- IT Audit Collaboration: Partner with the IT Audit team to evaluate the effectiveness of IT general controls (ITGC), access management, and data protection frameworks.
- Social Engineering: Design and execute simulated phishing and social engineering campaigns to test security awareness across client organizations.
- Client Presentation: Communicate complex technical findings effectively to both technical teams and senior management/audit committees.
Qualifications & Requirements:
- Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- Experience: 2 to 5 years of hands-on experience in penetration testing and ethical hacking (experience in audit, consulting, or professional services firms is a strong plus).
- Certifications (At least one is highly desirable):
- OSCP (Offensive Security Certified Professional)
- eJPT / eWPT (eLearnSecurity)
- CEH (Certified Ethical Hacker)
- CISA / CRISC (A plus for integrated IT audit and risk knowledge)
Technical Skills:
- Proficiency with industry-standard testing tools (e.g., Burp Suite, Metasploit, Nmap, Wireshark, Nessus).
- Deep understanding of OS (Linux/Windows), network protocols, web architecture, and OWASP Top 10.
- Familiarity with cybersecurity standards and compliance frameworks (e.g., ISO 27001, NIST, PCI-DSS).