We are seeking a skilled Cyber Security professional with proven expertise in manual penetration testing across web applications, APIs, and mobile applications (Android & iOS). The candidate must demonstrate hands-on testing capabilities beyond automated tool usage, with a robust focus on identifying and exploiting real-world vulnerabilities.Key Responsibilities
- Conduct manual penetration testing of web applications, APIs, and mobile applications.
- Identify, exploit, and document vulnerabilities including authentication flaws, authorization bypasses, injection attacks, insecure storage, and business logic issues.
- Collaborate with development teams to provide actionable remediation guidance.
- Prepare detailed assessment reports highlighting findings, risks, and recommendations.
- Stay updated with the latest security threats, exploits, and testing methodologies.
Required Skills
- Strong expertise in Web Application Penetration Testing.
- Hands-on experience in Mobile Application Security (Android & iOS).
- Proficiency in API Testing for REST/GraphQL endpoints.
- Solid understanding of Application Security and OWASP Top 10.
- Basic knowledge of Networking fundamentals to support penetration testing.
- Ability to perform manual testing without relying solely on automated tools (e.g., MobSF, Burp Suite defaults).
Preferred Qualifications
- Years of relevant experience in manual penetration testing (to be verified during screening).
- Track record of completed manual assessments across web, mobile, and API applications.
- Certifications (OSCP, CEH, etc.) are not mandatory, but practical expertise is essential.
What Were Looking For
- Analytical mindset with strong problem-solving skills.
- Clear communication skills for reporting and stakeholder discussions.
- Passion for cybersecurity and continuous learning.