Prescient Security
Penetration Testing
Skills
Job description
Penetration Tester (Mid–Senior Level)
Location - Remote - India
Experience Level - 2-5 years
As a Penetration Tester, you will be responsible for executing penetration testing engagements through client delivery with minimal oversight. You will independently perform testing activities, identify and exploit vulnerabilities, and produce high-quality client deliverables with clear, actionable remediation guidance.
You will assess web applications, APIs, networks, and/or cloud environments using a combination of automated tools and manual techniques. This includes configuring and operating testing tools, developing proof-of-concepts to demonstrate impact, and clearly documenting findings.
You will also participate in client-facing activities such as scoping discussions, kickoff calls, and report reviews, and are expected to communicate technical concepts effectively to both technical and non-technical audiences. In addition to delivery, you will contribute to the overall quality and evolution of the testing program by performing QA, Re-Tests, peer reviews, supporting internal tooling and methodology improvements, and sharing knowledge with other team members.
Must Have
Offensive Security Certification
Experience testing web applications and APIs (REST, SOAP, XML, JSON) and thick client
Key Responsibilities
Execute penetration testing engagements, across web applications, APIs, networks, and cloud environments
Identify, exploit, and document vulnerabilities with clear supporting evidence and proof-of-concept
Develop practical, risk-based remediation guidance
Produce high-quality, client-ready reports
Participate in client-facing calls including scoping, kickoff, and report reviews
Perform QA reviews of peer deliverables
Contribute to internal tools, research, and methodology improvements
Support and collaborate with team members to maintain delivery quality and consistency
Handle sensitive client information with confidentiality and professionalism
Qualifications & Experience:
Strong understanding of networks, web/mobile applications, and common security vulnerabilities (e.g., OWASP Top 10, common CVEs)
Industry-relevant certifications (SANS, Offensive Security, eLearn Security, etc.)
Experience testing web applications and APIs (REST, SOAP, XML, JSON)
Familiarity with modern web frameworks (e.g., Angular, Bootstrap)
Experience with scripting languages such as Python, Bash, PowerShell, or similar
Knowledge of vulnerabilities including XSS, SQL Injection, XXE, SSRF, deserialization, file inclusion/path traversal, authentication flaws, and remote code execution
Ability to develop proof-of-concepts and clearly demonstrate impact
Strong written and verbal communication skills
Ability to work independently and as part of a team