About the role
HR Bamboos is hiring on behalf of a E-commerce company for a Penetration Test Lead. We’re looking for an experienced offensive security professional to lead complex security assessments and Red Team engagements, uncover meaningful attack paths, validate security controls, and help strengthen security across applications, infrastructure, and cloud environments.
Responsibilities
- Lead and execute penetration tests across web and mobile applications, APIs, networks, infrastructure, cloud, Kubernetes, and containerized environments
- Define assessment scope, testing methodologies, Rules of Engagement, severity criteria, and reporting standards
- Conduct hands-on security testing, source code reviews, and vulnerability validation, with a focus on business impact and risk
- Design and lead Red Team and adversary simulation exercises to uncover realistic attack paths and validate security controls
- Work closely with SOC and Blue Team teams to assess and improve detection and response capabilities
- Produce clear technical reports with practical remediation guidance and track remediation through to completion
- Partner with Engineering, Development, DevOps, and SRE teams to integrate security testing into the SDLC and CI/CD pipelines
- Re-test remediated vulnerabilities and validate the effectiveness of security fixes
- Lead and mentor penetration testing engineers and review findings from internal and external assessments
- Track security and remediation metrics and support security investigations when required
Requirements
- 6+ years of professional experience in Penetration Testing, Offensive Security, or a related field
- Extensive hands-on experience across web, mobile, API, network, infrastructure, and cloud security testing
- Strong experience in Red Team operations and MITRE ATT&CK-aligned adversary simulation
- Strong knowledge of OWASP, vulnerability exploitation, attack-path analysis, threat modeling, and security architecture
- Strong understanding of Linux and Windows security, authentication, authorization, databases, and middleware
- Hands-on experience assessing Kubernetes, containerized workloads, and cloud environments
- Proficiency with offensive security tools such as Burp Suite, Nmap, and Metasploit
- Strong scripting skills in Python, Bash, or Go for security automation and tooling
- Hands-on DevSecOps experience across CI/CD security testing, including SAST, DAST, SCA, secret scanning, container scanning, and IaC scanning
- Strong skills in vulnerability analysis, risk prioritization, and technical security reporting
- Strong technical leadership, mentoring, and security assessment quality management skills
- Strong communication skills across Engineering, Security, DevOps, and leadership teams
Nice to have
- Certifications such as OSCP, OSEP, OSWE, GPEN, or similar
- Experience with Active Directory security, privilege escalation, and lateral movement
- Experience with tools such as BloodHound, Nessus, SQLMap, Cobalt Strike, or similar platforms
- Experience conducting cloud security assessments across AWS, Azure, or GCP
Benefits
- Competitive benefits package
- Professional growth and development opportunities
If you are seeking a career growth, we would be delighted to hear from you.
We maintain the highest level of confidentiality throughout the recruitment process.
Apply for this role