Penetration Tester / Ethical Hacker (Offensive Security)
FyerxJob Description
This is a remote position.
Penetration Tester / Ethical Hacker (Offensive Security)
Job Details
- Employment Type: Contract
- Work Mode: Remote
- Location: Offshore
- Total Experience Required: 4 to 8 years
- Relevant Experience Required: 3+ years of dedicated offensive security penetration testing and red teaming experience
- Mandatory Certification: Offensive Security Certified Professional (OSCP) or GIAC Penetration Tester (GPEN)
Job Summary
We are seeking an experienced Penetration Tester to conduct rigorous, multi-vector offensive security assessments against our global network infrastructure, web applications, and cloud environments. The ideal candidate will emulate advanced persistent threat (APT) tactics, discover hidden exploit vulnerabilities, and write technical proof-of-concept reports to help software engineering and infrastructure teams systematically harden corporate defenses.
Key Responsibilities
- Execute comprehensive network and web application penetration tests, utilizing automated scanning suites alongside manual exploration tactics to expose system vulnerabilities.
- Conduct realistic red-teaming simulation campaigns, probing corporate defenses, orchestrating advanced social engineering scenarios, and bypassing physical perimeter monitoring configurations.
- Develop structural custom exploitation scripts (e.g., Python, PowerShell, Bash) to demonstrate vulnerability severity while respecting operational stability guidelines.
- Triage and evaluate cloud infrastructure entry vectors, assessing multi-tenant environment perimeters, microservice containers, API authentication weaknesses, and misconfigured access permissions.
- Document and present highly detailed vulnerability disclosure reports, assigning clear impact scoring (CVSS), defining business risk matrices, and detailing step-by-step technical remediation paths.
- Perform rigorous post-remediation verification sweeps, re-testing patched software frameworks, validated infrastructure updates, and newly implemented defensive logic barriers.
- Collaborate closely with blue-team defensive operators, providing specific threat behavior inputs to optimize SIEM monitoring rules and security log alerts.
Requirements
- 4 to 8 years of core cybersecurity technical experience, with 3+ dedicated years actively performing authorized penetration tests within enterprise frameworks.
- Strong technical mastery of standard exploitation tooling arrays (e.g., Burp Suite Pro, Metasploit, Nmap, Kali Linux), reverse engineering scripts, and manual payload construction.
- Deep structural understanding of the OWASP Top 10 web/API flaws, Windows/Linux kernel security architectures, privilege escalation techniques, and active directory exploit vectors.
- Mandatory certification: OSCP or GPEN.
Preferred Qualifications
- Offensive Security Certified Expert (OSCE) or Advanced Web Attacks and Exploitation (OSWE) credential.
- Experience testing complex enterprise platforms like Salesforce networks, custom SAP endpoints, or specialized Workday database connectivity pipelines.