Penetration Tester Job Description Summary We are seeking a highly motivated and skilled Penetration Tester to join our team. You will be responsible for identifying vulnerabilities in our systems and networks, mimicking attacker methods, and recommending security controls to mitigate risks. Responsibilities Identify potential attacker methods to exploit system and network vulnerabilities. Simulate social engineering attacks to uncover security gaps. Gather information about network topography and usage through technical analysis and open-source research. Conduct code reviews using security testing and code scanning tools. Recommend security controls to address vulnerabilities identified through testing. Conduct reviews of defensive measures and penetration testing of infrastructure and assets according to organizational policies. Perform technical and non-technical risk and vulnerability assessments. Maintain a deployable cyber defense audit toolkit based on industry best practices. Test for vulnerabilities in web applications, client applications, and standard applications. Conduct physical security assessments of servers, systems, and network devices. Report penetration testing and vulnerability assessment findings, including risk level, proposed mitigation, and details for reproducing test results. Explain the business impact of identified vulnerabilities to advocate for remediation. Present test findings, risks, and conclusions to both technical and non-technical audiences. Design simulated attacks that reflect the impact on the organization's business and users. Qualifications Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline.(Preferred) Professional certifications such as OSCP, OSWP, OSEP, GPEN, GWAPT, GMOB, GXPN, GWEB, GCPN, e WAPTX, or e CTHP.5-7 years of experience in a relevant field. Skills Advanced proficiency in conducting vulnerability scans and interpreting results. Intermediate proficiency in conducting penetration testing aligned with organizational policies and best practices. Advanced proficiency in developing insights about an organization's threat environment. Advanced proficiency in analyzing vulnerability and configuration data to identify cybersecurity issues. Advanced proficiency in mimicking threat behaviors. Intermediate proficiency in implementing adversary Tactics, Techniques, and Procedures (TTPs).
ملخص الوصف الوظيفي لأخصائي اختبار الاختراق: نحن نبحث عن أخصائي اختبار اختراق عالي التحفيز والمهارة للانضمام إلى فريقنا. ستكون مسؤولاً عن تحديد الثغرات في أنظمتنا وشبكاتنا، ومحاكاة أساليب المهاجمين، والتوصية بضوابط أمنية للتخفيف من المخاطر. المسؤوليات: تحديد أساليب المهاجمين المحتملة لاستغلال ثغرات النظام والشبكة. محاكاة هجمات الهندسة الاجتماعية للكشف عن الفجوات الأمنية. جمع معلومات حول تضاريس الشبكة واستخداماتها من خلال التحليل الفني والبحث في المصادر المفتوحة. إجراء مراجعات للكود باستخدام أدوات اختبار الأمن وفحص الكود. التوصية بضوابط أمنية لمعالجة الثغرات التي يتم تحديدها من خلال الاختبار. إجراء مراجعات للتدابير الدفاعية واختبار الاختراق للبنية التحتية والأصول وفقاً لسياسات المنظمة. إجراء تقييمات المخاطر والثغرات الفنية وغير الفنية. الحفاظ على مجموعة أدوات تدقيق دفاع سيبراني قابلة للنشر بناءً على أفضل الممارسات في الصناعة. اختبار الثغرات في تطبيقات الويب وتطبيقات العميل والتطبيقات القياسية. إجراء تقييمات أمنية مادية للخوادم والأنظمة وأجهزة الشبكة. إعداد تقارير عن نتائج اختبار الاختراق وتقييم الثغرات، بما في ذلك مستوى المخاطر، والتخفيف المقترح، وتفاصيل إعادة إنتاج نتائج الاختبار. شرح التأثير التجاري للثغرات المحددة للدعوة إلى المعالجة. عرض نتائج الاختبار والمخاطر والاستنتاجات لكل من الجماهير الفنية وغير الفنية. تصميم هجمات محاكاة تعكس التأثير على أعمال المنظمة ومستخدميها. المؤهلات: درجة البكالوريوس في الأمن السيبراني أو علوم الحاسوب أو تكنولوجيا المعلومات أو تخصص ذي صلة. (يفضل) شهادات مهنية مثل OSCP أو OSWP أو OSEP أو GPEN أو GWAPT أو GMOB أو GXPN أو GWEB أو GCPN أو eWAPTX أو eCTHP. 5-7 سنوات من الخبرة في مجال ذي صلة. المهارات: كفاءة متقدمة في إجراء مسح الثغرات وتفسير النتائج. كفاءة متوسطة في إجراء اختبار الاختراق بما يتماشى مع سياسات المنظمة وأفضل الممارسات. كفاءة متقدمة في تطوير رؤى حول بيئة التهديدات الخاصة بالمنظمة. كفاءة متقدمة في تحليل بيانات الثغرات والتكوين لتحديد مشكلات الأمن السيبراني. كفاءة متقدمة في محاكاة سلوكيات التهديد. كفاءة متوسطة في تنفيذ تكتيكات وتقنيات وإجراءات (TTPs) الخصم.