Skill diminta
Communication
Deskripsi
- Conduct initial reconnaissance by gathering information about target systems, including domains, IP addresses, and technologies in use.
- Identify target assets and potential attack vectors or entry points.
- Perform vulnerability assessments and security scans using tools such as Nessus, OpenVAS, Burp Suite, or equivalent security testing tools.
- Assess the level of access that can be obtained, evaluate potential data exposure, and determine the impact of identified vulnerabilities.
- Prepare comprehensive penetration testing reports, including findings, risk assessments, and remediation recommendations.
- Prioritize identified vulnerabilities based on their severity (Critical, High, Medium, and Low).
- Stay up to date with the latest hacking techniques, cybersecurity threats, and emerging attack methods.
- Continuously enhance technical expertise by adopting new penetration testing tools, techniques, and industry best practices.
- Bachelor's Degree (S1) in Computer Science, Information Technology, Cyber Security, Information Systems, or a related field.
- Minimum 1 year of professional experience in Penetration Testing or Offensive Security.
- Able to provide the required endpoint device(s) for conducting penetration testing activities.
Experience contributing to banking or financial services security programs, particularly in penetration testing and web application security assessments.
Hands-on experience performing penetration testing on web applications, mobile applications (iOS & Android), APIs, and network infrastructure.
Strong experience in conducting network and application vulnerability assessments, identifying security weaknesses, and providing practical remediation recommendations.
Proficient in performing penetration testing for various platforms, including iOS, Android, Web-based applications, API-based applications, and network environments.
- Ability to act as a trusted security advisor by providing recommendations and guidance on penetration testing best practices.
- Experience collaborating with application developers, project managers, and management teams to resolve security findings.
Capable of reviewing existing penetration testing practices, identifying key security risks, and recommending preventive controls and security improvements.
- Familiarity with industry standards and frameworks such as OWASP Top 10, OWASP Testing Guide, PTES, NIST, or MITRE ATT&CK is an advantage.
- Strong analytical, problem-solving, communication, and report-writing skills.