Senior Penetration Testing Engineer
Must-have:PythonJavaMobileSecurityLead
Job Responsibilities
- Conduct comprehensive penetration testing of the company's and clients' web systems, applications, and internal network environments, identifying and verifying security vulnerabilities;
- Independently execute the full penetration testing lifecycle: information gathering, vulnerability scanning, vulnerability verification, privilege escalation, lateral movement within internal networks, etc.;
- Perform in-depth analysis of common vulnerabilities including SQL injection, XSS, CSRF, command execution, insecure deserialization, and OWASP Top 10 vulnerabilities, and provide remediation recommendations;
- Conduct code audits covering Java frameworks (Spring, Spring Boot, Spring MVC, MyBatis, etc.) and source-level identification of common web vulnerabilities;
- Perform mobile application (APP) security testing, including decompilation, hardening/reinforcement detection, static/dynamic analysis, and API penetration testing;
- Independently prepare penetration testing reports and communicate technical findings with project teams and clients;
- Participate in red team/blue team exercises and cyber defense drills, taking on responsibilities such as monitoring and analysis, attack attribution, and vulnerability remediation;
- Maintain familiarity with security frameworks such as MAS TRM, DORA, PCI DSS, ISO 27001, and SOC 2;
- Assist in delivering enterprise information security training to enhance internal security awareness.
Requirements
Basic Requirements
- Bachelor's degree or above in Computer Science, Computer Engineering, or a related field;
- 5+ years of experience in penetration testing / information security, with experience on both the client side and security vendor (consulting) side preferred;
- Strong ability to work independently, capable of taking on a project lead role and independently liaising with clients and project teams.
Technical Skills
- Proficient in end-to-end penetration testing methodology, with hands-on experience in internal network penetration testing (tunneling via ICMP/LCX/SSH, pass-the-hash, pass-the-ticket, lateral movement via WMI/PsExec, etc.);
- Proficient with security scanning and penetration testing tools such as AWVS, Nmap, SQLMap, Burp Suite, and AppScan;
- Capable of conducting Java code audits, familiar with tools such as Fortify and Eclipse, and vulnerability identification methods for common frameworks;
- Proficient in Python development, with the ability to independently write security tools (directory scanners, subdomain scanners, C-segment scanners, protocol brute-forcing tools, PoC/exploit development, etc.);
- Familiar with mobile application security testing, including APP decompilation (JADX, apktool), hardening/reinforcement identification, and dynamic testing with Frida;
- Familiar with common middleware attack techniques and host security inspection procedures.
Nice to Have
- Holds security certifications such as OSCP, OSWE, CREST, or has proof of original CVE disclosures;
- Project experience with high-security clients in financial services, government, or large state-owned enterprises;
- Experience participating in large-scale red team, purple team, or threat-led penetration testing engagements;
- Experience in security technical sharing/training, or an active personal technical blog/open-source project portfolio.