The R Programmer II at the Center for Biostatistics in AIDS Research will enhance operational efficiency through developing R programs and collaborating with researchers on statistical programming.
Penetration Testing
📜 Description
- Execute penetration testing engagements with minimal supervision.
- Assess applications and infrastructure using automated tools and manual testing techniques.
- Identify, validate, exploit, and document security vulnerabilities with clear evidence.
- Produce high-quality, client-ready penetration testing reports with technical findings.
- Participate in client-facing activities, including scoping discussions and report reviews.
- Contribute to internal security research and improvements to testing methodologies.
🛠️ Requirements
- 2–5 years of professional experience in penetration testing or offensive security.
- Industry-recognized offensive security certification or equivalent practical experience.
- Strong practical experience testing web applications and APIs.
- Understanding of common security vulnerabilities and established security frameworks.
- Experience with vulnerabilities including XSS, SQL injection, and remote code execution.
- Proficiency with scripting or automation languages such as Python or Bash.
- Strong written and verbal communication skills.
✨ Benefits
- Fully remote working opportunity within India.
- Full-time employment.
- Opportunity to work on diverse penetration testing engagements across applications, APIs, networks, and cloud environments.
- Exposure to real-world cybersecurity challenges and a broad range of technologies and attack surfaces.
- Opportunities to contribute to security research, internal tooling, and testing methodology improvements.
- Collaborative environment with opportunities for peer learning
- Professional development
- Client-facing experience across security assessments, scoping, kickoff sessions, and report reviews.
- Opportunity to strengthen offensive security expertise while working on varied client environments.
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Penetration Testing professional based in India.
This remote role offers the opportunity to conduct hands-on security assessments across web applications, APIs, networks, and cloud environments.
You will independently execute penetration testing engagements, identify vulnerabilities, and demonstrate their real-world impact through practical proof-of-concepts.
The position combines automated security tooling with manual testing techniques to uncover complex and meaningful security weaknesses.
You will translate technical findings into clear, actionable remediation guidance and polished client-ready reports.
The role also includes direct interaction with clients through scoping discussions, kickoff meetings, and report reviews.
Beyond individual engagements, you will contribute to quality assurance, peer reviews, internal research, tooling, and improvements to testing methodologies.
It is well suited to a security professional who combines strong offensive security skills with clear communication, independence, and a collaborative mindset.
Accountabilities
-
Execute penetration testing engagements across web applications, APIs, networks, and cloud environments with minimal supervision.
-
Assess applications and infrastructure using a combination of automated tools and manual testing techniques.
-
Identify, validate, exploit, and document security vulnerabilities with clear evidence and practical proof-of-concepts.
-
Evaluate vulnerabilities across areas such as authentication, authorization, injection, XSS, SQL injection, XXE, SSRF, deserialization, file inclusion, path traversal, and remote code execution.
-
Develop practical, risk-based remediation recommendations that help clients address identified security weaknesses.
-
Configure and operate penetration testing tools and develop supporting scripts or tooling where appropriate.
-
Produce accurate, high-quality, client-ready penetration testing reports with clear technical findings and business-relevant context.
-
Participate in client-facing activities, including scoping discussions, project kickoff calls, technical discussions, and report reviews.
-
Perform quality assurance reviews and peer reviews of security assessment deliverables.
-
Contribute to internal security research, tooling, testing methodologies, and continuous improvement initiatives.
-
Collaborate with other security professionals to maintain consistent delivery quality and share technical knowledge.
-
Handle sensitive client information responsibly, maintaining confidentiality and professionalism throughout engagements.
-
2–5 years of professional experience in penetration testing, offensive security, or a closely related cybersecurity discipline.
-
Industry-recognized offensive security certification or equivalent practical experience; certifications from organizations such as SANS, Offensive Security, or eLearnSecurity are valued.
-
Strong practical experience testing web applications and APIs, including REST, SOAP, XML, and JSON-based services.
-
Experience with thick-client applications and familiarity with modern web technologies and frameworks such as Angular and Bootstrap.
-
Strong understanding of computer networks, web and mobile applications, common security vulnerabilities, and established security frameworks such as the OWASP Top 10.
-
Knowledge of common CVEs and the ability to assess and exploit vulnerabilities in realistic environments.
-
Experience with vulnerabilities including XSS, SQL injection, XXE, SSRF, insecure deserialization, file inclusion/path traversal, authentication flaws, and remote code execution.
-
Ability to develop proof-of-concepts that clearly demonstrate the potential impact and exploitability of identified vulnerabilities.
-
Proficiency with scripting or automation languages such as Python, Bash, PowerShell, or similar.
-
Strong written and verbal communication skills, with the ability to explain technical security concepts to both technical and non-technical audiences.
-
Ability to work independently with limited oversight while also collaborating effectively within a distributed security team.
-
Strong attention to detail, analytical thinking, and commitment to producing accurate, high-quality client deliverables.
-
Fully remote working opportunity within India.
-
Full-time employment.
-
Opportunity to work on diverse penetration testing engagements across applications, APIs, networks, and cloud environments.
-
Exposure to real-world cybersecurity challenges and a broad range of technologies and attack surfaces.
-
Opportunities to contribute to security research, internal tooling, and testing methodology improvements.
-
Collaborative environment with opportunities for peer learning, technical knowledge sharing, and professional development.
-
Client-facing experience across security assessments, scoping, kickoff sessions, and report reviews.
-
Opportunity to strengthen offensive security expertise while working on varied client environments.
Requirements
Benefits
Similar jobs
Licensed Therapist – Adult Psychotherapy – Remote California – 1099 (LCSW, LMFT, LPCC, Psychologist)
Provide virtual psychotherapy to adult clients while developing individualized treatment plans and delivering culturally responsive care in a fully remote setting.
Telehealth Transitional Care Nurse Practitioner
As a Telehealth Transitional Care Nurse Practitioner, you will conduct virtual visits to support patients post-discharge, ensuring safe recovery and reducing readmission risks.
Ohio MD/DO - Telemedicine Primary Care Physician
Telemedicine Family/Internal Medicine Providers will deliver high-quality primary care through a telemedicine-first approach, ensuring continuity of care and flexibility in scheduling.
Virtual Elementary & Middle School Tutors
Certified educators are needed to provide engaging virtual tutoring for K-8 students in math and ELA, adapting instruction to meet individual needs.
