Conduct end-to-end penetration testing on web systems, mobile apps, and internal networks for the company and its clients, identifying and validating security vulnerabilities.
Independently execute the full pentest lifecycle: reconnaissance, vulnerability scanning, vulnerability validation, privilege escalation, and internal network lateral movement.
Perform in-depth analysis of common and OWASP Top 10 vulnerabilities (SQL injection, XSS, CSRF, command injection, deserialization, etc.) and provide remediation guidance.
Perform source code audits, covering Java frameworks (Spring, SpringBoot, SpringMVC, MyBatis) and common vulnerability patterns at the code level.
Conduct mobile (APP) security testing, including decompilation, hardening/packer detection, static/dynamic testing, and API-level penetration testing.
Independently author penetration test reports and liaise directly with project teams and clients.
Participate in red team / national-level cyber defense exercises, handling attack monitoring, traceback analysis, and remediation.
Support Multi-Level Protection Scheme (MLPS Level 3) security assessments.
Contribute to internal security awareness training programs.
Requirements
Basic Requirements
Bachelor's degree or above in Computer Science or a related field.
5+ years of experience in penetration testing / information security, ideally spanning both in-house and security-services (consulting) roles.
Strong ability to work independently, including owning client and project-team communication as a project lead.
Technical Skills
Proficient in the full penetration testing methodology, including internal network lateral movement (tunneling via ICMP/LCX/SSH, pass-the-hash, pass-the-ticket, WMI/PsExec lateral movement, etc.).
Skilled with AWVS, Nmap, SqlMap, Burp Suite, AppScan, and other scanning/testing tools.
Capable of Java source code auditing, familiar with Fortify, Eclipse, and vulnerability tracing across common frameworks.
Proficient in Python; able to independently build security tools (directory brute-forcers, subdomain scanners, C-segment scanners, protocol crackers, PoCs/exploits, etc.).
Experienced in mobile security testing — APP decompilation (AndroidKiller, apktool), hardening/packer identification, dynamic testing with Drozer, etc.
Familiar with common middleware attack techniques and host security inspection procedures.