Penetration Testing Specialist

Urgent
Apply Now

Job Description

We are seeking a highly skilled and proactive Penetration Testing Specialist to join our Risk Advisory & IT Audit team. In this role, you will play a critical part in assessing and strengthening our clients’ cybersecurity posture. You will simulate real-world cyberattacks across systems, networks, and applications to identify security vulnerabilities before they can be exploited, translating technical findings into actionable business insights for client leadership.

Key Responsibilities:

  • Penetration Testing & Assessments: Execute comprehensive internal/external penetration tests across web applications, mobile apps, network infrastructure, and cloud environments for clients.
  • Vulnerability Management: Perform routine vulnerability scans, validate identified risks, and evaluate their potential operational and business impact.
  • Report Writing & Consultation: Draft clear, detailed technical and executive reports outlining vulnerabilities, risk levels, and prioritized remediation strategies.
  • IT Audit Collaboration: Partner with the IT Audit team to evaluate the effectiveness of IT general controls (ITGC), access management, and data protection frameworks.
  • Social Engineering: Design and execute simulated phishing and social engineering campaigns to test security awareness across client organizations.
  • Client Presentation: Communicate complex technical findings effectively to both technical teams and senior management/audit committees.

Qualifications & Requirements:

  • Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Experience: 2 to 5 years of hands-on experience in penetration testing and ethical hacking (experience in audit, consulting, or professional services firms is a strong plus).
  • Certifications (At least one is highly desirable):
  1.  OSCP (Offensive Security Certified Professional)
  2.  eJPT / eWPT (eLearnSecurity)
  3.  CEH (Certified Ethical Hacker)
  4.  CISA / CRISC (A plus for integrated IT audit and risk knowledge)

Technical Skills:

  • Proficiency with industry-standard testing tools (e.g., Burp Suite, Metasploit, Nmap, Wireshark, Nessus).
  • Deep understanding of OS (Linux/Windows), network protocols, web architecture, and OWASP Top 10.
  • Familiarity with cybersecurity standards and compliance frameworks (e.g., ISO 27001, NIST, PCI-DSS).