Source description
About the role
Candidates must demonstrate robust manual pen testing skills in both web applications and mobile (preferably Android and iOS). Basic tool-driven testing (like MobSF scans) is insufficient; hands-on manual testing experience is mandatory. Networking knowledge is preferred but thick client testing is not currently required. Any certification is not mandatory Screening must include verifying years of relevant experience and number of completed manual assessments. Key Responsibilities Assist in the technical scoping of security testing activities based on client requirements and architecture reviews. Execute manual penetration testing across multiple domains, including: o Web Application Penetration Testing o Mobile Application Penetration Testing o Web Services / API Penetration Testing o Network Penetration Testing o Thick Client Penetration Testing Conduct focused security research when not deployed on active engagements. Analyze and understand complex application, infrastructure, and solution architecture designs to identify security weaknesses. Provide consultative guidance to stakeholders on vulnerabilities identified, including explicit and actionable remediation recommendations, both verbally and in writing. Prepare high-quality assessment reports with concise risk articulation and business-relevant recommendations. Enhance and update penetration testing methodologies, processes, playbooks, and standards documentation. Maintain technical proficiency through ongoing learning, certifications, and structured training paths. Effectively communicate the services, capabilities, and value proposition of the penetration testing team to internal and external stakeholders. Leverage automation and scripting, including AI-assisted and AI-integrated approaches, to improve testing efficiency and coverage. Support vulnerability research and exploit development activities using AI-enabled techniques where appropriate. Perform security testing for .
More at CLOUDXTREME LLC