Jobiglo

No results.

Mid-Level Penetration Tester

DeepStrike · Le Caire

Mid 🇬🇧 English
Penetration testing Manual security testing IDOR BOLA Privilege escalation Injection vulnerabilities SSRF OAuth JWT Networking fundamentals Operating systems Network protocols JavaScript Go Active Directory Source code review

Job description

About the role

DeepStrike is seeking a mid‑level penetration tester to perform real‑world security assessments for international clients. You will work independently on web applications, APIs, mobile apps, cloud environments, and network infrastructure, focusing on manual testing and business‑logic vulnerabilities.

Key responsibilities

  • Conduct manual penetration testing of web applications, REST/GraphQL APIs, mobile (Android/iOS) apps, and network infrastructure.
  • Identify, validate, and document vulnerabilities such as authentication flaws, IDOR/BOLA, privilege escalation, injection, SSRF, and account takeover scenarios.
  • Analyze complex workflows to uncover issues that automated tools may miss.
  • Produce detailed vulnerability reports with reproduction steps, impact analysis, and remediation guidance.
  • Communicate findings directly with clients and assist development teams in remediation.
  • Retest and verify fixes, collaborate with other testers, and mentor junior engineers.
  • Stay up‑to‑date with emerging attack techniques, tools, and security research.

Required profile

  • 2–4+ years of hands‑on penetration testing experience.
  • Strong problem‑solving, analytical, and written communication skills in English.
  • Ability to work independently, manage projects, and meet deadlines.
  • Comfortable discussing technical findings with both technical and non‑technical stakeholders.

Required skills

  • Manual penetration testing of web applications, APIs, mobile apps, and networks.
  • Deep knowledge of HTTP, OAuth, JWT, and modern web architectures.
  • Understanding of networking fundamentals, operating systems, and common protocols.
  • Experience with Python, Bash, JavaScript, or Go scripting.
  • Familiarity with cloud platforms (AWS, Azure, GCP) and Active Directory.
  • Source‑code review and bug‑bounty or vulnerability research is a plus.

What we offer

  • Opportunity to work on challenging, real‑world security engagements for global clients.
  • Collaborative environment with a focus on continuous learning and knowledge sharing.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec DeepStrike.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 month ago

Expires 2 weeks from now

26 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

DeepStrike

Le Caire