Overview
We are seeking a technical Senior Security Engineer for the Penetration Testing function. This role is expected to independently lead penetration testing engagements, serve as a technical escalation point for the team, mentor junior consultants, review assessment quality, and provide operational continuity for the Penetration Testing Lead when required.
Key Responsibilities
- Lead and execute web, mobile, API, network, cloud and Active Directory penetration tests
- Lead engagements from scoping, execution and reporting through stakeholder presentations
- Review penetration testing reports and technical deliverables for quality, consistency and accuracy
- Provide technical escalation support for junior consultants and VM analysts
- Mentor team members through coaching, report reviews and technical workshops
- Support engagement planning, estimation and resource allocation across concurrent assessments
- Drive methodology improvements, testing standards and automation initiatives
- Support remediation discussions with business and technology stakeholders
- Act as delegated operational lead when required
Person Specifications
Qualifications
- Minimum 3 to 5 years of hands-on penetration testing experience
- Strong expertise across Web, Mobile, API, Network, Active Directory and Cloud security testing
- Demonstrated experience leading penetration testing engagements independently
- Experience mentoring junior consultants and performing technical quality reviews
- Strong understanding of Active Directory attack paths, privilege escalation and post-exploitation techniques
- Experience assessing AWS and/or Azure cloud environments
- Ability to write scripts and automate offensive security workflows
- Excellent written and verbal English communication skills
- Exposure to AI security testing, including LLM prompt injection, agent abuse, indirect prompt injection, tool-chain security review and AI application security assessment
Preferred Experience
- Resource planning and engagement scheduling
- Coordination of multiple concurrent penetration testing engagements
- Red team operations, C2 infrastructure and phishing simulations
- Code review and secure development knowledge
- Experience in Intelligence-led penetration testing or threat-led penetration testing
- Experience building testing methodologies, reporting standards and QA processes
Preferred Certifications
- OSCP (preferred)
- CRTP
- OSWE
- GIAC certifications
- Relevant cloud security certifications