Web Application Penetration Tester

4 days ago


Taguig, National Capital Region, Philippines WTW Full time

On-site - Taguig Fresh Graduate/Student Bachelor Full-time

Job Description

Description

A penetration tester is responsible for assessing the security of web applications and its underlying infrastructure to identify vulnerabilities and weaknesses that could be exploited by attackers. Their role involves conducting thorough assessments and penetration tests to uncover potential security risks and provide recommendations for mitigation.

The role will work closely alongside the rest of the Penetration Testing team, Business units and other Cyber team.

We are looking for a collaborative team player, with a good technical knowledge in web application and infrastructure penetration testing. The successful candidate will contribute to and work as part of a global multi-disciplined security community with clear vision and direction, and top-down support across the business.

The Role

  • Vulnerability Assessment: Conducting comprehensive assessments of web applications and Infrastructure to identify security vulnerabilities, such as cross-site scripting (XSS), SQL injection, authentication flaws, insecure configurations, poor host device and service configurations, and use these to penetrate deeper into the application/server.
  • Penetration Testing: Performing controlled attacks on web applications, APIs, infrastructure, and simulate real-world hacking attempts and identify potential entry points for attackers. This involves utilizing various techniques, tools, and methodologies to exploit vulnerabilities and gain access.
  • Security Analysis: Analyzing the results of penetration tests to assess the severity of identified vulnerabilities, their potential impact on the system and the business, and the likelihood of exploitation.
  • Reporting and Documentation: Preparing detailed reports that document the findings, including identified vulnerabilities, attack vectors, and recommendations for remediation. These reports typically outline the risks associated with each vulnerability and provide guidance on how to mitigate them.
  • Remediation Support: Collaborating with developers and system administrators to assist in the remediation of identified vulnerabilities. This may involve providing guidance on secure coding practices, recommending security controls, or validating the effectiveness of implemented fixes.
  • Stay Up to Date: Keeping abreast of the latest web application and infrastructure vulnerabilities, attack techniques, security tools, and industry best practices. This includes staying informed about emerging threats and trends in web applications and infrastructure.
  • Ethical Approach: Conducting all testing and assessment activities within a legal and ethical framework, ensuring that the organization's systems and data are not compromised or harmed during the process.
  • Continuous Improvement: Engaging in professional development activities, such as attending conferences, participating in training programs, and obtaining relevant certifications, to enhance knowledge and skills in cyber security.
Qualifications
The Requirements
Minimum Criteria
  • Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.
  • Technical Knowledge: A strong understanding of web technologies, programming languages (e.g., HTML, CSS, JavaScript, PHP, Python), and web application architecture is essential. Knowledge of networking fundamentals, operating systems, and databases is also beneficial.
Skills
  • Web Application Security: In-depth knowledge of web application vulnerabilities, common attack techniques, and mitigation strategies. Strong understanding of OWASP Top 10 vulnerabilities is crucial.
  • Infrastructure Security: Working knowledge of different on-prem and cloud builds (IaaS, PaaS, SaaS), in-depth understanding of operating system and its common flaws.
  • Penetration Testing Techniques: Proficiency in various penetration testing methodologies, tools, and frameworks. Experience with manual testing techniques, automated vulnerability scanners, and exploit frameworks is necessary.
  • Programming and Scripting: Proficiency in at least one programming language (e.g., Python, Ruby, or JavaScript, etc.) to write custom scripts and tools. Understanding SQL queries for database testing is also important.
  • Analytical and Problem-Solving Skills: Ability to analyze complex web application environments, identify vulnerabilities, and exploit them. Strong problem-solving skills to understand attack vectors and recommend appropriate countermeasures.
Holds Relevant Industry Certification/s Or Equivalent Like The Following
  • CEH – Certified Ethical Hacker
  • OSCP – Offensive Security Certified Professional
  • GPEN – GIAC Penetration Tester
  • PNPT – Practical Network Penetration Tester
  • Burp Suite Certified Practitioner
  • eWAPT/eWAPTx – eLearning Web Application Penetration Tester

WTW is an Equal Opportunity Employer.

Working Location

Rizal Dr, Taguig City, National Capital Region, PH

If the position requires you to work overseas, please be vigilant and beware of fraud.

#J-18808-Ljbffr
  • Penetration Tester

    4 weeks ago


    Taguig, National Capital Region, Philippines Nityo Infotech Full time

    The RequirementsMinimum Criteria:Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.Technical Knowledge: A strong understanding of web technologies, programming...


  • Taguig, National Capital Region, Philippines Nityo Infotech Full time

    Minimum Criteria:-- Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.-- Technical Knowledge: A strong understanding of web technologies, programming languages (e.g.,...

  • Penetration Tester

    2 weeks ago


    Taguig, National Capital Region, Philippines Nityo Infotech Full time

    The RequirementsMinimum Criteria:Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.Technical Knowledge: A strong understanding of web technologies, programming...


  • Taguig, National Capital Region, Philippines JobsAvenuePH Full time

    Senior Penetration TesterJob Description• Perform penetration testing which includes internet, intranet, web application, wireless,social engineering, physical penetration testing.• Execute penetration testing projects using the established methodology, tools and rules ofengagements.• Execute red team assessments to highlight gaps impacting...

  • Penetration Tester

    4 weeks ago


    Taguig, National Capital Region, Philippines GSS PH Full time

    Qualifications:At least 6 mos – 2 years of experience for in Penetration Testing Experienced in Vulnerability Assessment and Penetration Testing of the following areas:Web Application (Non-Negotiable) (Web Application experience only for Staff level is okay)API (Non-Negotiable)MobileNetworkPhysical Penetration TestInfrastructureExperienced in exploitation...

  • Penetration Tester

    2 weeks ago


    Taguig, National Capital Region, Philippines GSS PH Full time

    Qualifications:At least 6 mos – 2 years of experience for in Penetration Testing Experienced in Vulnerability Assessment and Penetration Testing of the following areas:Web Application (Non-Negotiable) (Web Application experience only for Staff level is okay)API (Non-Negotiable)MobileNetworkPhysical Penetration TestInfrastructureExperienced in exploitation...


  • Taguig, National Capital Region, Philippines GSS PH Full time

    Qualifications:At least 4+ years of experience in Penetration Testing (6 mos – 2 years of experience for Staff level)Experienced in Vulnerability Assessment and Penetration Testing of the following areas:Web Application (Non-Negotiable) (Web Application experience only for Staff level is okay)API (Non-Negotiable)MobileNetworkPhysical Penetration...


  • Taguig, National Capital Region, Philippines JobsAvenuePH Full time

    Senior Penetration TesterJob Description• Perform penetration testing which includes internet, intranet, web application, wireless,social engineering, physical penetration testing.• Execute penetration testing projects using the established methodology, tools and rules ofengagements.• Execute red team assessments to highlight gaps impacting...


  • Taguig, National Capital Region, Philippines Manpower Core Group Inc. Full time

    • Perform penetration testing which includes internet, intranet, web application, wireless,social engineering, physical penetration testing.• Execute penetration testing projects using the established methodology, tools and rules ofengagements.• Execute red team assessments to highlight gaps impacting organizations security postures.• Identify and...


  • Taguig, National Capital Region, Philippines Manpower Core Group Inc. Full time

    • Perform penetration testing which includes internet, intranet, wireless, web application, socialengineering, and physical penetration testing.• Execute red team scenarios to highlight gaps impacting organizations security postures.• Ability to work both independently as well as lead a team of technical testers on penetration testingand red team...


  • Taguig, National Capital Region, Philippines JobsAvenuePH Full time

    Penetration Testing ManagerJob Description• Perform penetration testing which includes internet, intranet, wireless, web application, socialengineering, and physical penetration testing.• Execute red team scenarios to highlight gaps impacting organizations security postures.• Ability to work both independently as well as lead a team of technical...


  • Taguig, National Capital Region, Philippines Asurion Full time

    About AsurionAsurion is a leading provider of technology solutions and services, dedicated to helping people protect and enjoy the devices they love.We're seeking an experienced Application Penetration Tester to join our team. In this role, you will assist us in developing truly secure products by providing best-in-class application security penetration...


  • Taguig, National Capital Region, Philippines WTW Full time

    About the JobWe are looking for a highly skilled Penetration Testing Engineer to join our team at WTW. As a Penetration Testing Engineer, you will be responsible for conducting penetration tests to identify vulnerabilities and weaknesses in our web applications and infrastructure.ResponsibilitiesVulnerability Assessment: Conducting comprehensive assessments...


  • Taguig, National Capital Region, Philippines Nityo Infotech Full time

    Job Summary:Nityo Infotech is seeking a skilled Web Application Threat Hunter to join our team. As a Web Application Threat Hunter, you will play a critical role in identifying and mitigating web application threats. Your expertise will help us ensure the security and integrity of our online presence.About the Role:This is an excellent opportunity for...


  • Taguig, National Capital Region, Philippines GSS PH Full time

    GSS PH is committed to delivering top-notch cybersecurity solutions. As a Penetration Testing Expert, you will play a critical role in ensuring the security and integrity of our systems. Your expertise will help us identify and address potential vulnerabilities, thereby safeguarding our assets and protecting our clients' interests.Your primary responsibility...

  • Penetration Tester

    2 weeks ago


    Taguig, National Capital Region, Philippines Nityo Infotech Full time

    Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements,Technical Knowledge: A strong understanding of web technologies, programming languages (e.g., HTML, CSS, JavaScript,...


  • Taguig, National Capital Region, Philippines 360-365 Marketing OPC Full time

    Join Our TeamWe are 360-365 Marketing OPC, a leading marketing company, seeking a skilled Quality Assurance Software Engineer to help us deliver high-quality web applications.About the RoleThe successful candidate will be responsible for quality control and assurance of web pages, ensuring that they meet the required standards. This involves working closely...


  • Taguig, National Capital Region, Philippines Asurion Full time

    Job DescriptionWe're looking for an experienced Application Penetration Tester to join our team at Asurion. In this role, you will be responsible for performing comprehensive application and system penetration tests to identify vulnerabilities and risks within our products and enterprise systems.About YouYou have a strong background in computer science or...


  • Taguig, National Capital Region, Philippines Staff4Me Full time

    At Staff4Me, we are looking for a highly skilled Web Application Specialist to develop and maintain user-friendly web applications using the Vue.js framework. The ideal candidate will have a strong understanding of UI/UX design principles and be able to transform them into functional web applications.Main ResponsibilitiesImplement user interfaces using...


  • Taguig, National Capital Region, Philippines Hunter's Hub, Inc. Full time

    Required Skills and QualificationsStrong knowledge of mobile responsive single-page applications and progressive web application using vue.JS (vuex and vue-router)Experience in Java developmentFamiliarity with RESTful APIs to connect web applications to back-end servicesProficient understanding of web markup, including HTML5, CSS3, XML and JSONProficient...