- Workplace
- Onsite
- Type
- Full-time
- Department
- Engineering
- Education
- Bachelor
- Source
- RecruiterFlow
Description
Location: Taguig, Philippines
Work Setup: Onsite
Compensation Range: up to ₱80,000 per month
Compensation Flexibility: Open to negotiation for highly qualified candidates.
KEY RESPONSIBILITIES
-
Conduct vulnerability assessments and penetration testing (VAPT) on web and mobile applications, following established security testing methodologies and frameworks.
-
Prepare detailed assessment reports outlining identified vulnerabilities, findings, and remediation recommendations in accordance with the client's preferred reporting format, when available.
-
Provide technical assistance and consultation to development and remediation teams to support the resolution of identified security vulnerabilities.
-
Organize and facilitate meetings or consultation sessions, as needed, to coordinate and complete VAPT activities.
-
Independently manage assigned activities, project schedules, and tickets to ensure timely completion of deliverables.
-
Submit regular progress reports to immediate supervisors, providing updates on assessment activities, findings, and outstanding issues.
-
Maintain the confidentiality and security of all client information throughout assessment and reporting activities.
REQUIRED QUALIFICATIONS
-
Bachelor's degree in Information Technology, Computer Science, or a related field.
-
At least 3-5 years of hands-on experience conducting web and mobile application vulnerability assessments and penetration testing using the OWASP Top 10 testing framework.
-
Working experience with open-source and commercial security testing tools, such as Kali Linux, Metasploit, Qualys, Nessus, Burp Suite, and OWASP ZAP.
-
Working knowledge of web application and mobile application development, including common application architectures and security considerations.
PREFERRED QUALIFICATIONS
-
Ability to prepare clear, detailed VAPT reports that communicate technical findings and remediation recommendations to both technical and non-technical audiences.
-
Relevant cybersecurity certifications, such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or equivalent industry certifications.
-
Experience providing security consultation and collaborating with development teams to remediate application vulnerabilities.
REQUIRED SKILLS & TECHNOLOGIES
-
Vulnerability Assessment & Penetration Testing: Web application VAPT, mobile application VAPT, vulnerability identification, validation, and remediation recommendations.
-
Security Frameworks: OWASP Top 10 and application security testing methodologies.
-
Security Testing Tools: Kali Linux, Metasploit, Qualys, Nessus, Burp Suite, OWASP ZAP, and equivalent tools.
-
Application Development: Working knowledge of web and mobile application development, architecture, and common security vulnerabilities.
-
Reporting & Documentation: VAPT assessment reports, technical documentation, progress reporting, and remediation guidance.
-
Project & Activity Management: Schedule management, ticket ownership, progress tracking, and coordination of VAPT activities.
-
Core Competencies: Analytical thinking, problem-solving, communication, attention to detail, stakeholder collaboration, and confidentiality.