What you will do**
- Conduct penetration testing of web applications, APIs, networks, infrastructure, Active Directory, and other systems.
- Identify vulnerabilities using both automated tools and manual testing techniques.
- Validate found vulnerabilities, confirm their real impact, and exclude false positives.
- Assess vulnerabilities in terms of common attack techniques and security risks.
- Provide clear and practical recommendations for vulnerability remediation to Development and IT teams.
- Prepare structured reports on penetration testing results for internal stakeholders and clients.
- Perform re-testing after vulnerabilities have been fixed.
- Participate in the improvement of internal security testing approaches and methodologies.
What we expect
- 4**+ years of practical experience** in penetration testing, ethical hacking, or offensive security.
- Strong knowledge in the areas of: Web Application, Penetration Testing, API Security Testing, Network Penetration Testing, Active Directory Security Testing.
- Practical experience with tools such as Burp Suite, Nmap, Metasploit, Nuclei and similar.
- Ability to manually verify vulnerabilities and distinguish real security issues from false positives.
- Good understanding of OWASP Top 10 and common attack techniques.
- Experience in preparing technical reports on penetration testing results.
- Ability to clearly explain security findings to both technical and non-technical stakeholders.
What we offer:
- Remote work format (WW, excluding Russia).
- Schedule: full-time, 5/2.
- Probation period: 3 months.
📩 Contact for application: @rec_atss