Job Description
Position: Web Application Penetration Tester
Location: Guadalajara, Mexico
Department: Professional Services
Position Type: Full-Time / On-Site
Job Overview
Seeking a skilled Web Application Penetration Tester to join our Professional Services team. This role involves performing web application, API, and mobile application penetration tests. The successful candidate will lead and mentor junior team members, support pre-sales activities, and engage in client development.
Key Responsibilities
- Conduct web application, API, and mobile application penetration tests.
- Lead and mentor junior penetration testers to enhance their technical capabilities.
- Support pre-sales scoping and provide technical support during client engagements.
- Develop and maintain client relationships.
- Work independently on tasks with minimal supervision and collaborate effectively within a team environment.
Qualifications for Success
Consulting:
- Minimum of 4 years of consulting experience.
Web Application Assessments:
- At least 4 years of recent experience in web application assessments.
- Certifications such as OSCP, OSWE, or similar.
API Testing:
- Experience in testing APIs.
Mobile Application Testing:
- Proficiency in testing both iOS and Android applications.
Vulnerability Assessment and Penetration Testing:
- Familiarity with well-known methodologies for vulnerability assessment and penetration testing.
- Knowledge of web application design and implementation concepts.
- Strong understanding of various cloud providers and application configuration and deployment.
Information Security Fundamentals:
- At least 5 years of experience in information security.
- Bachelor's degree (or higher) in a related field.
- Certifications such as GSEC, GCIH, CISSP, or Security+.
Technical Skills:
- Expert knowledge of common vulnerabilities, exploits, and attacks used in penetration testing.
- Familiarity with multiple programming or scripting languages such as C, Java, Ruby, Perl, or Python.
Desired (But Not Required):
- Experience with social engineering tactics, techniques, and procedures.
- Proficient programming capabilities with experience in software development or quality assurance.
- General knowledge of network penetration testing.
- Understanding of Payment Card Industry (PCI) penetration testing concepts.
- Experience in threat modeling, adversary emulation, or long-duration Red Team exercises.