Penetration Tester

Converse BankYerevanstaffampublished 09/01/2026
Must-have:PythonCloudMobileSecurity
Machine translation — original language: Armenian.Show original

Converse Bank is looking for a Penetration Testing specialist to join the team for the purpose of assessing the security of the Bank's information systems, network infrastructure, Web and Mobile applications, and APIs.

  • Perform Penetration Testing of the Bank's internal and external information systems, network infrastructure, Web and Mobile applications, and APIs to identify vulnerabilities, weaknesses, and potential information security risks.
  • Perform Vulnerability Assessment, including manual testing, validation, and exploitability assessment of discovered vulnerabilities.
  • Perform security testing of Windows, Active Directory, and Linux infrastructures, including Privilege Escalation, Credential Access, and Lateral Movement scenarios.
  • Perform security testing of Web applications and APIs, including Authentication/Authorization Flaws, IDOR, Injection, SSRF, XSS, File Handling, Business Logic, and other vulnerabilities.
  • Assess the potential for further attack development using discovered vulnerabilities and their possible impact on the Bank's information systems and infrastructure.
  • Prepare technical reports, including descriptions of discovered vulnerabilities, proofs, risk and impact assessment, as well as practical recommendations for their remediation.
  • Perform retesting of remediated vulnerabilities to confirm the effectiveness of the measures taken and the actual elimination of vulnerabilities.
  • Collaborate with stakeholders in the processes of analyzing and remediating discovered vulnerabilities.
  • Stay updated on modern information security threats, vulnerabilities, and attack techniques, and apply the acquired knowledge in Penetration Testing processes.
  • Participate in the improvement of Penetration Testing methodologies, tools, and processes.
  • Participate in the implementation of separate Red Team / Adversary Emulation scenarios for the purpose of modeling attack chains and assessing the effectiveness of Detection/Response capabilities.
  • Practical experience in the Penetration Testing / Security Testing / Offensive Security field or evidence of relevant practical skills. CTF, Home Lab, educational or personal projects, portfolios, and professional certifications may also be considered. /For Middle level, at least 2 years of relevant work experience is preferred./
  • Higher education or equivalent professional experience in information security, cybersecurity, information technology, computer science, or related fields. /Students are also considered./
  • Practical understanding of Penetration Testing and Vulnerability Assessment processes, including vulnerability discovery, manual testing, validation, and exploitability assessment. Practical experience gained through educational, laboratory, or personal projects is also acceptable.
  • Good understanding of TCP/IP, DNS, HTTP/HTTPS, TLS, VPN, and the principles of basic network protocols, network segmentation, and corporate network infrastructures.
  • Knowledge of Windows and Linux operating systems, as well as the structure and basic security mechanisms of Active Directory.
  • Knowledge of Web application and API architecture, common attack vectors, and vulnerabilities, including the OWASP Top 10.
  • Practical application skills of core Penetration Testing tools: Burp Suite, Nmap, Kali Linux, as well as knowledge of Metasploit, BloodHound, Impacket, NetExec/CrackMapExec, or equivalent tools.
  • General understanding of common attack techniques and phases, including Privilege Escalation, Credential Access, Lateral Movement, Persistence, and other relevant techniques.
  • General knowledge of core Penetration Testing and Offensive Security methodologies and frameworks: OWASP Web Security Testing Guide (WSTG), PTES, MITRE ATT&CK, NIST SP 800-115.
  • Basic knowledge of at least one of Python, PowerShell, or Bash, and the ability to understand, modify, or create simple scripts.
  • Ability to clearly document and present discovered vulnerabilities, their exploitability, impact, and risk.
  • Analytical thinking, a creative and non-standard approach to problem-solving, and the ability to learn independently and continuously develop professional skills.
  • Ability to work both independently and in a team, as well as the ability to communicate effectively with different technical teams.
  • High level of professional ethics, responsibility, and strict adherence to requirements for maintaining confidential information.
  • English proficiency: a sufficient level for reading technical documentation, security research, Vulnerability Advisories, and professional materials.

Nice to have

  • Experience in Red Team / Adversary Emulation exercises or attack chain modeling.
  • Experience in in-depth Active Directory security testing and Attack Path analysis.
  • Experience in Mobile Application Security Testing, Container/Cloud Security, or other additional directions.
  • Experience in security testing of information systems and infrastructures of banking or financial organizations.
  • Presence of professional certifications: eJPT, PJPT, PNPT, CPTS, OSCP/OSCP+, CRTP/CRTO, eWPT/eWPTX, or equivalent.
  • Participation in Bug Bounty programs, as well as practical training and skill development on specialized information security platforms such as Hack The Box, TryHackMe, PortSwigger Web Security Academy, Cisco Networking Academy, OffSec Proving Grounds, PentesterLab, or equivalent platforms.

What are we looking for in a candidate

  • Practical interest in Offensive Security and Penetration Testing directions, the ability to discover, test, and assess the risk of real vulnerabilities, as well as a willingness to continuously develop technical knowledge and practical skills.
  • The main focus is on the Penetration Testing direction, while the Red Team / Adversary Emulation component is considered an additional and gradually developing direction.