Web Application Penetration Tester
4 days ago
On-site - Taguig Fresh Graduate/Student Bachelor Full-time
Job DescriptionDescription
A penetration tester is responsible for assessing the security of web applications and its underlying infrastructure to identify vulnerabilities and weaknesses that could be exploited by attackers. Their role involves conducting thorough assessments and penetration tests to uncover potential security risks and provide recommendations for mitigation.
The role will work closely alongside the rest of the Penetration Testing team, Business units and other Cyber team.
We are looking for a collaborative team player, with a good technical knowledge in web application and infrastructure penetration testing. The successful candidate will contribute to and work as part of a global multi-disciplined security community with clear vision and direction, and top-down support across the business.
The Role
- Vulnerability Assessment: Conducting comprehensive assessments of web applications and Infrastructure to identify security vulnerabilities, such as cross-site scripting (XSS), SQL injection, authentication flaws, insecure configurations, poor host device and service configurations, and use these to penetrate deeper into the application/server.
- Penetration Testing: Performing controlled attacks on web applications, APIs, infrastructure, and simulate real-world hacking attempts and identify potential entry points for attackers. This involves utilizing various techniques, tools, and methodologies to exploit vulnerabilities and gain access.
- Security Analysis: Analyzing the results of penetration tests to assess the severity of identified vulnerabilities, their potential impact on the system and the business, and the likelihood of exploitation.
- Reporting and Documentation: Preparing detailed reports that document the findings, including identified vulnerabilities, attack vectors, and recommendations for remediation. These reports typically outline the risks associated with each vulnerability and provide guidance on how to mitigate them.
- Remediation Support: Collaborating with developers and system administrators to assist in the remediation of identified vulnerabilities. This may involve providing guidance on secure coding practices, recommending security controls, or validating the effectiveness of implemented fixes.
- Stay Up to Date: Keeping abreast of the latest web application and infrastructure vulnerabilities, attack techniques, security tools, and industry best practices. This includes staying informed about emerging threats and trends in web applications and infrastructure.
- Ethical Approach: Conducting all testing and assessment activities within a legal and ethical framework, ensuring that the organization's systems and data are not compromised or harmed during the process.
- Continuous Improvement: Engaging in professional development activities, such as attending conferences, participating in training programs, and obtaining relevant certifications, to enhance knowledge and skills in cyber security.
The Requirements
Minimum Criteria
- Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.
- Technical Knowledge: A strong understanding of web technologies, programming languages (e.g., HTML, CSS, JavaScript, PHP, Python), and web application architecture is essential. Knowledge of networking fundamentals, operating systems, and databases is also beneficial.
- Web Application Security: In-depth knowledge of web application vulnerabilities, common attack techniques, and mitigation strategies. Strong understanding of OWASP Top 10 vulnerabilities is crucial.
- Infrastructure Security: Working knowledge of different on-prem and cloud builds (IaaS, PaaS, SaaS), in-depth understanding of operating system and its common flaws.
- Penetration Testing Techniques: Proficiency in various penetration testing methodologies, tools, and frameworks. Experience with manual testing techniques, automated vulnerability scanners, and exploit frameworks is necessary.
- Programming and Scripting: Proficiency in at least one programming language (e.g., Python, Ruby, or JavaScript, etc.) to write custom scripts and tools. Understanding SQL queries for database testing is also important.
- Analytical and Problem-Solving Skills: Ability to analyze complex web application environments, identify vulnerabilities, and exploit them. Strong problem-solving skills to understand attack vectors and recommend appropriate countermeasures.
- CEH – Certified Ethical Hacker
- OSCP – Offensive Security Certified Professional
- GPEN – GIAC Penetration Tester
- PNPT – Practical Network Penetration Tester
- Burp Suite Certified Practitioner
- eWAPT/eWAPTx – eLearning Web Application Penetration Tester
WTW is an Equal Opportunity Employer.
Working LocationRizal Dr, Taguig City, National Capital Region, PH
If the position requires you to work overseas, please be vigilant and beware of fraud.
#J-18808-Ljbffr-
Penetration Tester
4 weeks ago
Taguig, National Capital Region, Philippines Nityo Infotech Full timeThe RequirementsMinimum Criteria:Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.Technical Knowledge: A strong understanding of web technologies, programming...
-
Senior Penetration Tester
2 weeks ago
Taguig, National Capital Region, Philippines Nityo Infotech Full timeMinimum Criteria:-- Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.-- Technical Knowledge: A strong understanding of web technologies, programming languages (e.g.,...
-
Penetration Tester
2 weeks ago
Taguig, National Capital Region, Philippines Nityo Infotech Full timeThe RequirementsMinimum Criteria:Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.Technical Knowledge: A strong understanding of web technologies, programming...
-
Senior Penetration Tester
3 weeks ago
Taguig, National Capital Region, Philippines JobsAvenuePH Full timeSenior Penetration TesterJob Description• Perform penetration testing which includes internet, intranet, web application, wireless,social engineering, physical penetration testing.• Execute penetration testing projects using the established methodology, tools and rules ofengagements.• Execute red team assessments to highlight gaps impacting...
-
Penetration Tester
4 weeks ago
Taguig, National Capital Region, Philippines GSS PH Full timeQualifications:At least 6 mos – 2 years of experience for in Penetration Testing Experienced in Vulnerability Assessment and Penetration Testing of the following areas:Web Application (Non-Negotiable) (Web Application experience only for Staff level is okay)API (Non-Negotiable)MobileNetworkPhysical Penetration TestInfrastructureExperienced in exploitation...
-
Penetration Tester
2 weeks ago
Taguig, National Capital Region, Philippines GSS PH Full timeQualifications:At least 6 mos – 2 years of experience for in Penetration Testing Experienced in Vulnerability Assessment and Penetration Testing of the following areas:Web Application (Non-Negotiable) (Web Application experience only for Staff level is okay)API (Non-Negotiable)MobileNetworkPhysical Penetration TestInfrastructureExperienced in exploitation...
-
Senior Penetration Tester
3 weeks ago
Taguig, National Capital Region, Philippines GSS PH Full timeQualifications:At least 4+ years of experience in Penetration Testing (6 mos – 2 years of experience for Staff level)Experienced in Vulnerability Assessment and Penetration Testing of the following areas:Web Application (Non-Negotiable) (Web Application experience only for Staff level is okay)API (Non-Negotiable)MobileNetworkPhysical Penetration...
-
Senior Penetration Tester
7 days ago
Taguig, National Capital Region, Philippines JobsAvenuePH Full timeSenior Penetration TesterJob Description• Perform penetration testing which includes internet, intranet, web application, wireless,social engineering, physical penetration testing.• Execute penetration testing projects using the established methodology, tools and rules ofengagements.• Execute red team assessments to highlight gaps impacting...
-
Senior Penetration Tester
2 weeks ago
Taguig, National Capital Region, Philippines Manpower Core Group Inc. Full time• Perform penetration testing which includes internet, intranet, web application, wireless,social engineering, physical penetration testing.• Execute penetration testing projects using the established methodology, tools and rules ofengagements.• Execute red team assessments to highlight gaps impacting organizations security postures.• Identify and...
-
Penetration Testing Manager
2 weeks ago
Taguig, National Capital Region, Philippines Manpower Core Group Inc. Full time• Perform penetration testing which includes internet, intranet, wireless, web application, socialengineering, and physical penetration testing.• Execute red team scenarios to highlight gaps impacting organizations security postures.• Ability to work both independently as well as lead a team of technical testers on penetration testingand red team...
-
Penetration Testing Manager
3 weeks ago
Taguig, National Capital Region, Philippines JobsAvenuePH Full timePenetration Testing ManagerJob Description• Perform penetration testing which includes internet, intranet, wireless, web application, socialengineering, and physical penetration testing.• Execute red team scenarios to highlight gaps impacting organizations security postures.• Ability to work both independently as well as lead a team of technical...
-
Penetration Testing Professional
24 hours ago
Taguig, National Capital Region, Philippines Asurion Full timeAbout AsurionAsurion is a leading provider of technology solutions and services, dedicated to helping people protect and enjoy the devices they love.We're seeking an experienced Application Penetration Tester to join our team. In this role, you will assist us in developing truly secure products by providing best-in-class application security penetration...
-
Penetration Testing Engineer
4 days ago
Taguig, National Capital Region, Philippines WTW Full timeAbout the JobWe are looking for a highly skilled Penetration Testing Engineer to join our team at WTW. As a Penetration Testing Engineer, you will be responsible for conducting penetration tests to identify vulnerabilities and weaknesses in our web applications and infrastructure.ResponsibilitiesVulnerability Assessment: Conducting comprehensive assessments...
-
Web Application Threat Hunter
2 days ago
Taguig, National Capital Region, Philippines Nityo Infotech Full timeJob Summary:Nityo Infotech is seeking a skilled Web Application Threat Hunter to join our team. As a Web Application Threat Hunter, you will play a critical role in identifying and mitigating web application threats. Your expertise will help us ensure the security and integrity of our online presence.About the Role:This is an excellent opportunity for...
-
Penetration Testing Expert
4 hours ago
Taguig, National Capital Region, Philippines GSS PH Full timeGSS PH is committed to delivering top-notch cybersecurity solutions. As a Penetration Testing Expert, you will play a critical role in ensuring the security and integrity of our systems. Your expertise will help us identify and address potential vulnerabilities, thereby safeguarding our assets and protecting our clients' interests.Your primary responsibility...
-
Penetration Tester
2 weeks ago
Taguig, National Capital Region, Philippines Nityo Infotech Full timeEducation: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements,Technical Knowledge: A strong understanding of web technologies, programming languages (e.g., HTML, CSS, JavaScript,...
-
Web Application Tester
4 days ago
Taguig, National Capital Region, Philippines 360-365 Marketing OPC Full timeJoin Our TeamWe are 360-365 Marketing OPC, a leading marketing company, seeking a skilled Quality Assurance Software Engineer to help us deliver high-quality web applications.About the RoleThe successful candidate will be responsible for quality control and assurance of web pages, ensuring that they meet the required standards. This involves working closely...
-
Application Security Specialist
24 hours ago
Taguig, National Capital Region, Philippines Asurion Full timeJob DescriptionWe're looking for an experienced Application Penetration Tester to join our team at Asurion. In this role, you will be responsible for performing comprehensive application and system penetration tests to identify vulnerabilities and risks within our products and enterprise systems.About YouYou have a strong background in computer science or...
-
Web Application Specialist
4 days ago
Taguig, National Capital Region, Philippines Staff4Me Full timeAt Staff4Me, we are looking for a highly skilled Web Application Specialist to develop and maintain user-friendly web applications using the Vue.js framework. The ideal candidate will have a strong understanding of UI/UX design principles and be able to transform them into functional web applications.Main ResponsibilitiesImplement user interfaces using...
-
Web Application Architect
3 days ago
Taguig, National Capital Region, Philippines Hunter's Hub, Inc. Full timeRequired Skills and QualificationsStrong knowledge of mobile responsive single-page applications and progressive web application using vue.JS (vuex and vue-router)Experience in Java developmentFamiliarity with RESTful APIs to connect web applications to back-end servicesProficient understanding of web markup, including HTML5, CSS3, XML and JSONProficient...