
Posted 17 hours ago
Penetration Tester
WTWPenetration Tester
Requirements
Bachelor's degree in Computer Science or related field, Strong understanding of web technologies (HTML, CSS, JavaScript, PHP, Python), Knowledge of OWASP Top 10, Proficiency in penetration testing tools and frameworks, C1/C2 English proficiency, Relevant certifications (OSCP, CEH, or similar)
Skills
Penetration TestingWeb SecurityPython
About the role
Responsibilities
- Conduct comprehensive vulnerability assessments of web applications and infrastructure to identify risks like XSS, SQL injection, and authentication flaws.
- Perform controlled penetration tests on web applications, APIs, and infrastructure to simulate real-world hacking attempts.
- Analyze test results to assess the severity, potential business impact, and likelihood of exploitation for identified vulnerabilities.
- Prepare detailed technical reports documenting findings, attack vectors, and specific remediation recommendations.
- Collaborate with developers and system administrators to provide guidance on secure coding practices and validate implemented fixes.
- Stay current with emerging threats, attack techniques, and industry best practices in cybersecurity.
- Ensure all testing activities are conducted within a strict legal and ethical framework.
Requirements
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field (relevant experience may compensate).
- Strong understanding of web technologies including HTML, CSS, JavaScript, PHP, and Python.
- In-depth knowledge of the OWASP Top 10 vulnerabilities and mitigation strategies.
- Proficiency in penetration testing methodologies, manual testing techniques, and automated vulnerability scanners.
- Working knowledge of on-prem and cloud environments (IaaS, PaaS, SaaS) and operating system flaws.
- Ability to write custom scripts using languages such as Python, Ruby, or JavaScript.
- C1/C2 English proficiency in both spoken and written communication.
Preferred Qualifications
- Relevant industry certifications such as OSCP, CEH, GPEN, PNPT, or Burp Suite Certified Practitioner.
- Experience with eWAPT/eWAPTx certifications.
- Strong analytical and problem-solving skills for complex web application environments.
About the Company
WTW is a global multi-disciplined security community that provides professional services to help clients manage risk and protect their assets. We are committed to equal employment opportunity and fostering an inclusive culture for all colleagues.
ScoutJobs Agent
Get matches like this delivered daily
Sign up free — we'll pull jobs that fit your CV from across the web and rank them for you.
Get started — it's freePenetration Tester
WTW · Madrid
