About this role
Job title: Penetration Tester
About the Role
The i2c security team is seeking a dedicated security testing professional to perform vulnerability assessments and penetration testing across web applications, mobile apps, APIs, and network infrastructure. This role combines manual and automated testing within a strong security testing program and supports secure SDLC.
What You'll Do
- Conduct vulnerability assessments and penetration testing across web applications, mobile apps, APIs, and network infrastructure.
- Perform manual and automated security testing using tools such as Burp Suite, OWASP ZAP, Nessus, Nmap, and Metasploit.
- Execute security test cases aligned with OWASP Top 10, OWASP ASVS, API Security Top 10, and CWE/SANS Top 25.
- Identify, document, and report vulnerabilities with severity ratings (CVSS), proof-of-concept evidence, and remediation guidance.
- Conduct dynamic application security testing (DAST) and interactive testing (IAST) as part of CI/CD pipelines.
- Identify, validate, and reproduce vulnerabilities such as XSS, SQL Injection, CSRF, authentication weaknesses, authorization flaws, SSRF, security misconfigurations, and sensitive data exposure.
- Assess HTTP security headers, and TLS/SSL implementations.
- Perform cloud security assessments covering misconfigurations, and exposed services.
- Validate remediation efforts through retesting and track vulnerabilities to closure.
- Maintain and improve internal security testing tools, scripts, and automation frameworks.
- Stay current with emerging threats, zero-days, CVEs, and evolving attack techniques.
- Improve security testing processes, research emerging vulnerabilities and threats, mentor junior team members, and share technical knowledge across the team.
- Conduct secure design reviews, architecture reviews, and threat modeling activities during the software development lifecycle.
What We're Looking For
- Education: Bachelor's Degree.
- Experience: at least 1 year in security testing, vulnerability assessment, or related field.
- Skills: Hands-on experience with QA testing and security testing tools (e.g., Burp Suite, OWASP ZAP, Nessus, Nmap, Metasploit).
- Knowledge of OWASP Top 10, OWASP ASVS, API Security Top 10, CWE/SANS Top 25.
- Familiarity with DAST/IAST, CI/CD security integration, vulnerability remediation, and retesting.
- Strong documentation, reporting, and communication skills.
- Ability to identify, reproduce, and validate vulnerabilities (e.g., XSS, SQLi, CSRF) and to contribute to secure design reviews and threat modeling.
- Understanding of TLS/SSL, HTTP security headers, and basic cloud security concepts.
- Mentoring ability and willingness to share knowledge with the team.