Candidates must demonstrate robust manual pen testing skills in both web applications and mobile (preferably Android and iOS).
Basic tool-driven testing (like MobSF scans) is insufficient; hands-on manual testing experience is mandatory.
Networking knowledge is preferred but thick client testing is not currently required.
Any certification is not mandatory
Screening must include verifying years of relevant experience and number of completed manual assessments.
Execute manual penetration testing across multiple domains, including:
o Web Application Penetration Testing
o Mobile Application Penetration Testing
o Web Services / API Penetration Testing
o Network Penetration Testing
o Thick Client Penetration Testing