
Penetration Tester
- London
- Permanent
- Full-time
Location: London
Certification : OSCP / CREST / Cloud Certification (AWS/AZURE)
Skills: Penetration Testing (Cloud - AWS and GCP/Mobile (iOS - Android/Infra/Network)Role: We are looking for a senior penetration tester who has gained good experience in this area and he/she will be highly skilled pen tester/Red Teamer, will be having more deeper knowledge/understanding of (Cloud - AWS and GCP, Mobile -iOS - Android, Infrastructure Testing, Network Testing).Required Skills & Experience:
- Engage with respective Project owners and gather information on the respective requirement.
- Prepare Scoping document with attack path & test plan/scenarios/checklist.
- Ensure scope sign off received before progressing with Pen test.
- Hands-on and Core Experience in Cloud(AWS & GCP) Pen Testing.
- Hands-on and Core Experience Threat Modelling/Design Review.
- Hands-on and Core Experience in Network/Infra, for an instance, investigate Firewall/Server level, AD level, sitting inside the network/infrastructure and enumerating the same components at more deeper level in order to analyze the attack path.
- Hands-on and Core Experience in Mainframe Testing.
- Experience is various tools like Nessus pro, DNSExfiltrator, SharpExfiltrate, Maltego Pro etc. and for specific pen test activity, like for AD Pen Test tools like Tenable.ad etc, Cloud Testing Tools.
- Hands-on Experience in Mobile Security Testing (iOS and Android) - Static & Dynamic.
- Hand-on Experience in Web application Testing with deep knowledge of OWASP Top 10.
SAP as service providerWe use the following session cookies, which are all required to enable the website to function:
- "route" is used for session stickiness
- "careerSiteCompanyId" is used to send the request to the correct data center
- "JSESSIONID" is placed on the visitor's device during the session so the server can identify the visitor
- "Load balancer cookie" (actual cookie name may vary) prevents a visitor from bouncing from one instance to another