The Penetration Tester will conduct security assessments across web, mobile, API, and network environments. This role focuses on identifying vulnerabilities, documenting findings, and working closely with development and security teams to remediate risks. The ideal candidate has a solid foundation in offensive security techniques and is eager to grow within a product-focused security team.
+ ' ' +
- 2–4 years of hands-on experience in penetration testing across web applications, APIs, mobile, and network infrastructure.
- Solid knowledge of OWASP Top 10 (Web), OWASP API Security Top 10, and common vulnerability classes.
- Experience with penetration testing tools including Burp Suite, OWASP ZAP, Nmap, Metasploit, and Nessus/OpenVAS.
- Ability to perform thorough manual testing in addition to automated scanning.
- Understanding of network protocols, firewall rules, and common infrastructure misconfigurations.
- Basic knowledge of Active Directory environments and common attack techniques.
- Experience with both internal and external network assessments.
- Ability to document vulnerabilities clearly with CVSS scoring, proof of concept, and remediation guidance.
- Basic scripting skills in Python or Bash for automating tasks and extending tooling.
- Familiarity with CI/CD security concepts and integrating security scans into pipelines.
- Understanding of MITRE ATT&CK framework and the Cyber Kill Chain.
- Certifications preferred: OSWE, OSEP, OSCP, CAPE, CRTO or equivalent ones
+ ' ' +
- Opportunities for professional growth and development.
- Competitive salary and bonuses.
- Comprehensive insurance coverage.
- Supportive work environment.
- Visa Premium salary card.
- Corporate discounts and events.
- Additional vacation days.
- Discounted education and employee loans.
+ ' ' +
- Conduct penetration tests on web applications, APIs, mobile applications, and network infrastructure.
- Document and report vulnerabilities with clear severity ratings, supporting evidence, and remediation steps.
- Collaborate with Development and DevOps teams to validate remediations and re-test fixes.
- Participate in security assessments and code reviews alongside senior team members.
- Support the integration of DAST tools and security scans within CI/CD pipelines.
- Stay current with emerging attack techniques, CVEs, and security research.
- Assist in threat modeling and design review sessions.
Kapital Bank iş mühiti, əlavə fürsətlər və digər vakansiyaları görüntüləmək üçün Kapital Bank Life səhifəsinə keçid edin.
Vakansiyalardan daha tez xəbərdar olmaq üçün Telegram kanalımıza abunə olun!