Roles & Responsibilities
Vouch is currently working with a Singapore-based company that specializes in security solutions.
We are seeking an experienced Penetration Tester with strong expertise in source code review. The ideal candidate will not only possess hands-on experience in various domains such as web, network, mobile, thick-client, IoT, and cloud security but also demonstrate the ability to lead, mentor, and teach other team members. This role requires a deep understanding of security vulnerabilities, penetration testing methodologies, and the ability to perform thorough source code reviews to identify potential security flaws.
Primary Responsibilities:
- Perform detailed source code reviews to identify security vulnerabilities.
- Act as the domain expert in source code analysis.
- Perform hands-on penetration testing across multiple domains: web applications, networks, mobile applications, thick-client environments, IoT devices, and cloud platforms.
- Identify, exploit, and document security vulnerabilities.
- Create comprehensive reports that detail findings and recommended mitigations.
- Collaborate with team members to share knowledge and improve security testing methods.
- Conduct security assessments and audits of systems, applications, and networks.
- Keep updated on the latest security trends, vulnerabilities, and technologies to ensure a strong organizational security posture.
What I Am Looking For:
- At least 1-2 years of hands-on experience in penetration testing across various domains.
- Proven experience in performing and leading detailed source code reviews, with a strong understanding of secure coding practices.
- Desirable certifications like CREST, OSCP, or similar recognized penetration testing qualifications.
- In-depth knowledge of common security vulnerabilities
- Strong report writing and documentation skills, with the ability to explain technical issues to non-technical stakeholders.
EA License: 22C1396
EA Personnel: R1551466
Tell employers what skills you have
Mobile Application
Distributed Platforms
Security Assessments
Applications
Community Networks
Vulnerability
Exploitation
Security Technology
Source Code Reviews
Electronic Devices
Penetration Testing
Source Code development
research reports
Thin Client
Web Applications
collaborate with external team