Junior Penetration Tester
- Published on
About the Role
We are currently searching for a Junior Penetration Tester early in their career journey. In this position, your mandate will be to assess the security posture of our clients by identifying and exploiting vulnerabilities in networks, applications, and systems. With guidance from colleagues, you will conduct controlled security assessments, execute attack simulations, and document findings to support remediation efforts.
Key Responsibilities
- Conduct web, network, mobile, and API penetration tests to identify vulnerabilities.
- Support team assessments, simulating real-world attack scenarios.
- Develop and execute custom exploits, scripts, and attack chains.
- Conduct source code reviews for security weaknesses in applications.
- Assess cloud security in AWS, Azure, and GCP, along with containerized environments like Docker and Kubernetes.
- Collaborate with blue teams, SOC analysts, and developers to remediate findings.
- Write detailed technical reports and present findings to technical and non-technical stakeholders.
- Stay updated on zero-day vulnerabilities, APT tactics, and emerging threats.
- Participate in CTFs, security research, and bug bounty programs to refine skills.
About the Candidate
As an ideal candidate, you should be a smart and passionate developing pen tester with a strong interest in adversarial emulation and custom exploit development. You are a natural hacker with a founder’s mindset, eager to learn and collaborate, and thrive in a startup environment.
Key Qualifications
- 1-2 years of hands-on penetration testing experience.
- Proficiency in manual testing techniques beyond automated scanning.
- Knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
- Experience with Active Directory attacks, privilege escalation, and lateral movement.
- Skilled in the use of tools like Burp Suite, Nessus, Metasploit, and Kali Linux.
- Familiarity with scripting in Python, PowerShell, Bash, or Ruby.
- Excellent communication and interpersonal skills.
About the Company
Malleum is a premier cybersecurity consultancy that blends advanced offensive and defensive strategies to safeguard our customers. With a team known for its contributions to cybersecurity research at platforms like Black Hat and DEF CON, we excel at identifying and mitigating sophisticated threats. Large enterprises from various industries trust us for advanced adversarial emulation and critical support in managing their cyber frameworks. Governments rely on our precision and discretion to handle sensitive information securely, making a big impact with our deep technical expertise and commitment to clients.
We are looking for someone to join our accelerating startup, work with cutting-edge tech, and tackle critical problems in high-stakes engagements.