Gender: Any Age: From 25 to 35 Seniority Level: Expert Required Experience Year: Between 2 to 5 years Working days: Saturday to Wednesday Job Description At blubank, we are seeking talented, dynamic, and enthusiastic individuals as a Penetration Testing Secialist to join our friendly and professional team. If you’re looking for a workplace where you can grow and continuously learn, this opportunity is for you! Responsibilities: Perform manual and automated penetration testing on web applications, APIs, and related infrastructure. Identify vulnerabilities such as injection flaws, broken authentication, security misconfigurations, cross-site scripting (XSS), and other OWASP Top 10 issues. Conduct vulnerability assessments and provide detailed reports on findings, including severity ratings and remediation advice. Evaluate the effectiveness of existing security controls and recommend enhancements. Ensure that web applications meet regulatory compliance requirements (e.g., PCI DSS, GDPR). Follow industry standards such as OWASP, NIST, and ISO/IEC 27001 during security evaluations. Work with developers and IT teams to integrate security best practices during application development. Support incident response by simulating web-based attack scenarios and identifying potential vectors for exploitation. Prepare comprehensive penetration testing reports, including executive summaries and technical details. Maintain records of testing activities and track remediation efforts. Collaborate with software development teams to address vulnerabilities during the development lifecycle. Engage with external auditors and clients to explain testing methodologies and findings when required. Qualifications: Bachelor’s degree in Computer Science, Information Security, or a related field. Relevant certifications (e.g., OSCP, CEH, GPEN, GWAPT, or CISSP). 2-5 years of experience in web application penetration testing, vulnerability assessment, or a related field. Proven experience with tools such as Burp Suite, OWASP ZAP, Metasploit, and Ness In-depth understanding of web application technologies (HTML, JavaScript, CSS, REST APIs). Familiarity with common programming languages (e.g., Python, Node JS, Java, or JS). Knowledge of networking concepts, firewalls, and secure protocols. Strong analytical and problem-solving abilities. Excellent written and verbal communication skills for technical and non-technical audiences. Ability to prioritize and manage multiple projects under tight deadlines. Benefits: Work from home option Flexible working hours Training courses and professional development opportunities Military service project (Limited) Supplemental health insurance Team-building budget Performance-based bonuses Loans Lunch subsidies
|
Penetration Testing Specialist (Web) |