- Company Name
- Tanisha Systems, Inc
- Job Title
- Penetration Testing Engineer
- Job Description
-
**Job Title:** Penetration Testing Engineer
**Role Summary:**
Conduct in‑depth web, mobile, and API security testing for business‑critical applications. Use Burp Suite Professional and other tools to identify, exploit, and document vulnerabilities. Work with development, DevSecOps, and risk teams to embed secure SDLC practices and support remediation.
**Expectations:**
* 5–8 years of application/API penetration testing experience, with >3 years of hands‑on offensive testing.
* Expert proficiency with Burp Suite (Intruder, Repeater, Decoder, Extender) and a solid grasp of OWASP, MITRE ATT&CK, and CWE frameworks.
* Strong programming/scripting skills (Python, JavaScript, or Bash) and ability to create custom scripts or Burp extensions.
* Proven ability to produce clear, risk‑prioritized reports and to collaborate effectively with developers and security operations.
**Key Responsibilities:**
* Perform manual and automated penetration tests on web, mobile, and API endpoints.
* Execute REST and GraphQL API tests, including JWT, OAuth, and token manipulation.
* Develop proof‑of‑concept exploits, simulating attacker TTPs from MITRE ATT&CK.
* Document findings, impact, and mitigation recommendations; facilitate retesting post‑remediation.
* Integrate test results into CI/CD pipelines and contribute to secure coding guidelines.
* Stay current with emerging threats, CVEs, and offensive security tools; develop automation scripts to increase testing efficiency.
**Required Skills:**
* Burp Suite Professional (expert).
* OWASP ZAP, Nmap, Metasploit, SQLmap, DirBuster, Hydra, Ffuf.
* Deep understanding of OWASP Top 10 Web & API, CWE Top 25.
* Proficient with HTTP/HTTPS, REST, GraphQL, JSON, XML.
* Programming/scripting: Python, JavaScript, or Bash; design Burp extensions.
* Experience with APT‑style threat simulation, C2 tools (Cobalt Strike, Empire) optional.
* Knowledge of API gateways (Kong, Apigee), microservices, and cloud security (AWS, Azure, GCP) preferred.
**Required Education & Certifications:**
* Bachelor’s or Master’s in Computer Science, Information Security, or related field.
* Preferred certifications: OSCP, OSWE, OSEP, Burp Suite Certified Practitioner (BSCP), eWPTX, eCPPT, CEH, GWAPT, GPEN, GCPN.