We are seeking a highly skilled and relentless Penetration Tester to lead complex offensive security operations across modern web applications, mobile platforms, APIs, and hybrid network environments. This is not a scanner role we’re looking for someone who thrives in deep manual analysis, can creatively bypass hardened defenses, and pivot through segmented networks like a true adversary.
- Conduct advanced manual penetration testing across applications and infrastructure, uncovering business logic abuses, race conditions, and chained vulnerabilities beyond the scope of automated tools;
- Execute black-box and gray-box engagements with and without credentials, simulating persistent threat actors with advanced TTPs;
- Perform deep-dive manual secure code reviews across various tech stacks, identifying subtle implementation flaws in logic, cryptography, and access control;
- Develop custom tooling, payloads, or exploits when commercial or open-source solutions fall short;
- Participate in or lead red team engagements, including phishing, physical intrusion planning, and lateral movement through complex enterprise networks;
- Act as a strategic partner to DevSecOps and Product teams, proactively shaping secure architecture and mitigating threats early in the SDLC;
- Mentor junior team members and contribute to internal offensive R&D, methodology refinement, and tooling innovation.