Senior Penetration Testing Specialist

Apply for job
Müraciət üçün aşağıdakı email ünvanı köçürmək lazımdır.

Senior Penetration Testing Specialist

  • Deadline 4 October 2026
Apply for job
Müraciət üçün aşağıdakı email ünvanı köçürmək lazımdır.

Responsibilities:

  • Planning and conducting penetration tests of internal and external infrastructure (network, Active Directory, Windows/Linux servers);
  • Security assessment of web applications (OWASP Top 10, business logic vulnerabilities, authentication/authorization flaws);
  • Analysis of attack paths in Active Directory environments (Kerberoasting, ACL abuse, delegation vulnerabilities, lateral movement scenarios);
  • Assessing identified vulnerabilities based on their risk level and preparing technical and management-level reports;
  • Collaborating with infrastructure and application teams during the remediation process and conducting retesting of fixes;
  • Working closely with the SOC team to test and improve detection rules;
  • Participating in phishing simulations and social engineering assessments;
  • Security assessment of AI-based systems and LLM-integrated applications (prompt injection, jailbreak, data leakage, and test scenarios based on the OWASP Top 10 for LLM Applications);
  • Effective use of AI-based tools in penetration testing processes (reconnaissance, payload generation, and report preparation automation);
  • Managing the vulnerability management process: administration of Rapid7 and Tenable Nessus scanners, configuration of scan profiles, analysis of results, and false-positive filtering;
  • Analyzing the impact of new CVEs on the infrastructure and prioritizing them;
  • Defining the scope, planning, and leading the execution of penetration testing projects;
  • Mentoring team specialists, providing technical guidance, and ensuring the quality of prepared reports;
  • Developing and improving penetration testing methodologies, internal standards, and procedures;
  • Presenting test results to management and explaining risks in business terms.

Requirements:

  • At least 3 years of practical experience in information security, including at least 1 year of practical experience in penetration testing;
  • Practical certification requirement: OSCP or an equivalent certification — CRTO, GPEN, or similar. OSEP, OSWE, and CRTE certifications are considered an advantage;
  • Ability to independently plan and conduct network and infrastructure penetration tests and lead projects at the project level;
  • Practical experience in security assessment of Active Directory environments and a deep understanding of key attack paths;
  • Ability to manually test web applications, going beyond automated scan results to identify business logic, authentication, and authorization vulnerabilities;
  • Practical experience with vulnerability scanners: configuration of scans, triage, and validation of results using Tenable Nessus, Rapid7 InsightVM/Nexpose, or equivalent solutions;
  • Knowledge of post-exploitation, privilege escalation, and analysis of key security configurations in Windows and Linux systems;
  • Manual testing of API security, REST and GraphQL APIs, including Broken Object Level Authorization (BOLA/IDOR), mass assignment, and rate limiting bypass;
  • Cloud security knowledge, including basic penetration testing scenarios in AWS / Azure / GCP environments (IAM misconfiguration, S3 bucket exposure, metadata service abuse);
  • Understanding of security in containerized/microservices environments, including key Docker and Kubernetes misconfiguration points and container escape scenarios;
  • Automation of AI-oriented tasks in daily penetration testing activities;
  • Proficiency in at least one scripting language for test process automation and, when required, development of simple tools: Python, PowerShell, or Bash;
  • Ability to document findings in a clear, reproducible, and risk-based reporting format and provide specific remediation recommendations;
  • Experience in technical leadership or mentoring within a team and ability to independently manage complex projects;
  • Fluency in Azerbaijani;
  • Proficiency in English for working with technical documentation and reports.

Preferred Qualifications:

  • Additional certifications: OSEP, OSWE, CRTP/CRTE, BSCP, or equivalent practical certifications;
  • Understanding of EDR detection and evasion techniques;
  • Understanding of how attacks are reflected from a logging and detection perspective;
  • Experience with C2 frameworks: Cobalt Strike, Sliver, Havoc, or equivalent tools;
  • Participation in CTFs, HackTheBox/TryHackMe profiles, bug bounty experience, or personal security research, such as blog posts, CVEs, open-source tools, etc.;
  • Interest or practical experience in AI/LLM security: OWASP LLM Top 10, MITRE ATLAS, AI red teaming;
  • Familiarity with AI-assisted penetration testing tools: PentestGPT, Burp AI, and equivalent solutions

We Offer:

  • Meal allowance;
  • Annual performance bonuses;
  • Corporate health program: Voluntary insurance and special discounts for gyms; 
  • Access to Digital Learning Platforms.

Note: Only candidates who meet the requirements of the vacancy will be contacted for the next stage.

Interested candidates can send their CV to the e-mail address in the Apply for job button.

  • Daily0
  • Weekly635
  • Monthly1726