Penetration Tester at Bugcrowd

We are redirecting you to the source. If you are not redirected in 3 seconds, please click here.

Penetration Tester at Bugcrowd. Location Information: India. Bugcrowd is looking for a creative, enterprising, and intrinsically motivated individual to join our growing Security Operations team. As a Pentester, you’ll be part of a small but impactful team of individuals directly responsible for performing penetration tests and vulnerability assessments against a wide variety of targets!. The ideal candidate for the Pentester role is a quick learner of complex concepts, a consummate professional, and an effective communicator with proven excellence in executing projects in a timely and comprehensive manner. For this specific role, it is required that one has a strong understanding of common security issues and concepts such as the OWASP Top Ten, common pentesting/vulnerability assessment tools, general web/tech acumen, and a passion for delivering results. Having a history of performing webapp pentests or vulnerability assessments is preferred. Duties & Responsibilities. Perform penetration tests and vulnerability assessments against a wide variety of web applications.. Be thorough and comprehensive in coverage, as well as adhering to a strict methodology for completing the assessments.. Act decisively, independently, and confidently across a wide variety and range of circumstances and situations. This role includes a large amount of autonomy in day-to-day operations and comes with a high degree of implicit trust to be able to execute with minimal supervision. To this end, it’s critical that the right candidate also is able to demonstrate complete and total ownership of any/all responsibilities related to the role. . Provide verbose and detailed documentation for all interactions - while also exhibiting exemplary written and verbal communication skills in both internally and externally facing capacities.. Desired Skills & Experience:. History and experience with executing web application pen tests or vulnerability assessments (performed by hand, and not through a scanner).. Familiarity with and capable of using command line tools and utilities (Bash, SSH, grep, etc).. Understanding of how common security testing tools are utilized and to what purposes (examples include Burp, nmap, kali, metasploit, gobuster, etc).. Able to create a mental (or written) model of a target’s attack surface and understand what types of attacks would be commonly leveraged against targets of a particular genre.. Able to work in a cross-departmental capacity that can serve as a clear source of guidance for a wide range of security and bug bounty-related questions.. Able to independently find solutions to both technical and non-technical problems with no apparent answer (aggressive googling, stack overflow, etc).. At least vaguely familiar with at least one scripting language (python, ruby, bash, etc) to a degree of proficiency that simple tools can be made to help automate tasks, workflow, etc.. Working Conditions. The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.. Sitting and/or standing - Must be able to remain in a stationary position 50% of the time. Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.. Environment - remote, work-from-home 100% of the time.. ADA Statement. Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at [email protected].