Penetration Tester
Listed on 2026-01-13
-
IT/Tech
Cybersecurity, Systems Engineer, Security Manager, Data Security
We are seeking a skilled Penetration Tester with strong experience in CI/CD pipeline security to identify, assess, and mitigate security vulnerabilities across applications, infrastructure, and automated deployment environments. The role focuses on proactive security testing, secure Dev Ops practices, and strengthening systems against evolving threats.
Key ResponsibilitiesConduct penetration testing on web applications, APIs, networks, and cloud environments.
Perform security assessments of CI/CD pipelines
, including build, test, and deployment workflows.Identify vulnerabilities related to source code repositories, automation tools, container images, and secrets management
.Test authentication, authorization, session management, and access controls.
Assess API security, including token handling, rate limiting, and authorization flaws.
Execute static (SAST), dynamic (DAST), and dependency security testing within CI/CD processes.
Validate security of containerized environments (Docker, Kubernetes).
Simulate real-world attack scenarios and document findings with clear remediation guidance.
Collaborate with development and Dev Ops teams to implement secure-by-design practices.
Support incident response investigations and post-incident analysis when required.
2+ years of experience in penetration testing, application security, or ethical hacking
.Strong understanding of CI/CD pipelines and Dev Sec Ops methodologies.
Hands‑on experience securing tools such as Git Hub Actions, Git Lab CI, Jenkins, Azure Dev Ops, or similar
.Proficiency in web and API security testing (OWASP Top 10, OWASP API Top 10).
Experience with authentication mechanisms (JWT, OAuth2, SSO).
Knowledge of common vulnerabilities: SQLi, XSS, CSRF, SSRF, IDOR, RCE, misconfigurations.
Familiarity with Linux environments
, networking concepts, and cloud security fundamentals.
Penetration testing tools:
Burp Suite, Metasploit, Nmap, OWASP ZAP, Nikto
.CI/CD security tools:
Snyk, Trivy, Sonar Qube, Dependabot, Git Guardian
.Container and cloud security tools (experience preferred).
Scripting knowledge in Python, Bash, or Power Shell is an advantage.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).