
Penetration Tester
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Philippines.
• Execute thorough penetration testing engagements focused on enterprise infrastructure, networks, systems, and applications.
• Conduct both manual and automated security assessments to uncover vulnerabilities, weaknesses, and potential attack vectors.
• Analyze and exploit Active Directory environments, addressing misconfigurations, privilege escalation pathways, lateral movement opportunities, credential theft vulnerabilities, and excessive permissions or insecure delegation.
• Carry out network and system exploitation activities to confirm security weaknesses and evaluate their implications.
• Review security controls, hardening techniques, and defensive configurations within Active Directory environments.
• Simulate realistic attack scenarios to gauge organizational resilience against cyber threats.
• Create comprehensive technical reports detailing attack pathways, findings, business impact, proof-of-concept evidence, and remediation suggestions.
• Communicate technical findings to both technical and non-technical audiences.
• Collaborate with internal teams and clients to facilitate remediation efforts and offer guidance on security best practices.
• Keep abreast of emerging threats, attack techniques, exploitation methods, and security technologies.
• Demonstrated experience in conducting penetration tests across enterprise networks and infrastructure.
• In-depth knowledge of Windows environments and Active Directory security.
• Experience in identifying and exploiting vulnerabilities and attack vectors within Active Directory.
• Strong understanding of network protocols and architecture.
• Comprehensive understanding of Windows Server administration.
• Proficient understanding of authentication mechanisms such as Kerberos and NTLM.
• Strong grasp of privilege escalation techniques.
• Excellent knowledge of lateral movement methodologies.
• Practical experience with tools including BloodHound, Mimikatz, CrackMapExec, Impacket, Nmap, Burp Suite, Metasploit, and Responder.
• Familiarity with OWASP, NIST, and PTES security testing frameworks.
• Robust technical documentation and report-writing capabilities.
• Exceptional analytical, troubleshooting, and problem-solving skills.
• Competitive salary and performance-based bonuses.
• Comprehensive health and wellness benefits.
• Opportunities for professional development and training.
• Flexible working hours and remote work options.
• Collaborative and innovative work environment.
Ava Industries
EDITION
Healthcare Management Solutions, LLC
SPD Technology
Get handpicked remote jobs straight to your inbox weekly.