Location: Baku
Job Type: Full-time
Experience Level: Senior
Languages Required: Azerbaijani (required), English (required)
About the Role
We are seeking a highly skilled and experienced Senior Penetration Tester to join growing cybersecurity team. In this role, you will lead advanced security assessments across a variety of platforms including web, mobile, APIs, and infrastructure. You’ll play a vital role in red team operations, source code reviews, and simulating real-world attacks, helping our clients proactively identify and mitigate security vulnerabilities.
This is an opportunity to apply your offensive security expertise in a dynamic and collaborative environment, while driving continuous improvements in security posture across multiple domains.
Key Responsibilities
- Conduct advanced penetration tests on Web Applications, APIs, Mobile Applications, and Infrastructure in line with industry standards and methodologies.
- Perform source code reviews with a focus on .NET, Java, and occasionally PHP.
- Participate in or lead red team engagements that simulate real-world attacks and assess security resilience.
- Develop and present Proof-of-Concept (PoC) exploits to demonstrate the real-world impact of identified vulnerabilities.
- Prepare comprehensive reports, including technical findings, risk assessments, and actionable remediation strategies.
- Create executive summaries for non-technical stakeholders to support informed decision-making.
- Collaborate with development, DevOps, and infrastructure teams to support secure coding and effective vulnerability remediation.
Qualifications & Requirements
Education:
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.
Experience:
- Minimum of 3 years of hands-on experience in penetration testing.
Technical Expertise:
- Proven experience in conducting penetration tests across Web, API, Mobile, and Infrastructure environments.
- Strong knowledge of OWASP Top 10, MITRE ATT&CK, and offensive security best practices.
- Experience in red teaming engagements, including adversary simulation and detection evasion.
- Understanding of secure coding practices and remediation strategies.
- Ability to develop PoCs and demonstrate the business impact of vulnerabilities.
- Proficient in writing clear, concise reports tailored to both technical and non-technical audiences.
- Collaborative approach to working with internal teams on remediation and security improvements.
- Familiarity with scripting or programming languages such as Python, Bash, or JavaScript is a plus.
Preferred Certifications
- OSCP, OSWE, OSEP, CRTL, or equivalent offensive security certifications.
Core Competencies
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
- Attention to detail and commitment to quality
- Time management and prioritization
- Teamwork and cross-functional collaboration
- Proactive learning and adaptability
- Integrity and a strong work ethic
Why Join Us?
- Be part of a high-impact cybersecurity team tackling real-world security challenges
- Work on diverse projects with industry-leading tools and methodologies
- Continuous learning opportunities, including certification support
- Collaborative and supportive work environment
If you are interested in the position, please send your CV to [email protected] and do not forget to mention your salary expectation.