Responsibilities
- Web & Infrastructure Pentesting: Perform high-quality security audits, penetration tests, and vulnerability assessments on web applications and environments.
- SAST & Code Review: Execute Static Application Security Testing (SAST) to identify logical and security flaws within the source code. (If you aren’t an expert in specific SAST tools yet, we will provide the training, but a strong ability to read and understand code is essential).
- Technical Documentation: Create clear deliverables and “attack paths.” You must be able to present findings and security recommendations effectively to both technical teams and stakeholders.
- Tool Development: Propose and develop internal scripts or tools to improve the team’s auditing efficiency and automation.
- Client Collaboration: Act as a technical bridge, ensuring the quality of the service and responding to client requirements with a focus on problem-solving.
Qualifications
Minimum qualifications
- Experience: 2+ years of experience in Web Pentesting or Red Team environments.
- Programming Skills: Proficiency in reading and understanding code (e.g., Python, JavaScript, Java, .NET, or PHP). You should feel comfortable auditing logic within a codebase.
- Technical Expertise: Understanding and knowledge of OWASP methodology.
- Proven experience identifying and exploiting web application vulnerabilities.
- Knowledge of Linux/Windows OS and network fundamentals.
- Languages: English fluency (B2 level or higher).
- Soft Skills: Ability to explain complex technical concepts to non-technical people (humility is key).
Ideal qualifications
- Certifications: OSCP, eWPTX, OSWE, CRTO…
- SAST Experience: Familiarity with tools like Checkmarx, Fortify, SonarQube, or Snyk.
- Education: Degree in Computer Science, Telecommunications, or equivalent experience/self-taught background.
Who you are
We value humility and a collaborative spirit. We are looking for someone who isn’t afraid to ask “why” or “how,” who stays current with ethical hacking best practices, and who enjoys working in a highly collaborative environment. If you love breaking things but are even more passionate about understanding how they are built, we want to meet you.