ROLE DESCRIPTION
You will be a member of a strong community of internal penetration testers, with exposure to all parts of the firm and its most critical systems. The role involves penetration testing of a wide variety of applications, including web applications, infrastructure, and cloud. You will have access to the source code for most of the tested systems, enabling quick verification of your hypotheses.
In this role, you will join one of the most progressive Technology Risk teams in the industry , which continues to push the development of risk in preference to security within technology and the business. You will collaborate with technology teams on both in-house projects andexternal cloud adoptions to deliver secure products and solutions.
HOW YOU WILL FULFILL YOUR POTENTIAL
- Perform penetration tests and find impactful vulnerabilities in a wide variety of webapplications, cloud-based systems, and infrastructure platforms (e.g., banking websites,payment applications, authentication systems, core internal frameworks, criticalinfrastructure)
- Work with teams to recommend ways of addressing vulnerabilities and propose systematic improvements.
SKILLS AND EXPERIENCE WE ARE LOOKING FOR
Experience in penetration testing across the mentioned areas.Strong understanding of web security topics, ability to build exploit chains, and articulatethe impact of individual findings.Experience in analysing complex infrastructural systems by code review, server and cloud configuration analysis, reverse engineering, and fuzzing.Working knowledge of common security tools (Burp Suite, Wireshark, Ghidra, netcat)Familiarity with one or more languages (Java, JavaScript, Python, C++, C#)Well-versed with TCP / IP stack and network protocolsHigh-level knowledge of cryptography conceptsPREFERRED QUALIFICATIONS
Experience in adopting or crafting custom proof-of-concept exploitsKnowledge of common cloud products and solutionsBachelor of Science in Computer Science, Cyber-Security, or Information Security is preferredExperience or training in related disciplines, e.g. ,computer security, network security,network device management, IT administration, cloud security,and infrastructure pentesting is preferredCertificates (of equivalent knowledge) like OSCP, OSEP, OSWP