We're looking for an experienced Penetration Tester with 3-5+ years of hands-on offensive security experience within a consulting or professional services environment. The successful candidate will have proven experience performing web application, infrastructure, internal and external network, and Active Directory penetration testing while producing high-quality technical reports and remediation guidance. Strong proficiency with Burp Suite, Kali Linux, Metasploit, Nmap, Nessus, BloodHound, Impacket, and related offensive security tooling is expected, alongside scripting experience in Python, Bash, or PowerShell. Candidates should demonstrate a solid understanding of the OWASP Top 10, modern attack methodologies, and common enterprise technologies. Relevant certifications such as OSCP, PNPT, CRTP, CRTE, eCPPT, or eJPT are highly desirable. Excellent client communication, report writing, and the ability to manage multiple consulting engagements are essential.
About the Client
Our client is one of South Africa’s leading cybersecurity consultancies, delivering offensive security, advisory, managed security, and incident response services to enterprise organisations across multiple industries.
Working alongside experienced consultants, you will perform high-quality penetration testing engagements, identify security weaknesses, and provide clients with practical recommendations to strengthen their security posture.
Role Overview
Our client is seeking an experienced Penetration Tester to join their growing Offensive Security team.
This role is suited to someone who enjoys technical assessments across web applications, internal and external infrastructure, Active Directory environments, cloud platforms, and network security. You will work on multiple client engagements while producing high-quality technical reports and remediation guidance.
The ideal candidate has a consulting mindset, enjoys solving complex security problems, and can confidently communicate technical findings to both technical and business stakeholders.
Key Responsibilities
- Conduct penetration tests against web applications, APIs, internal and external infrastructure, wireless networks, and Active Directory environments.
- Perform vulnerability assessments and validate findings through manual exploitation.
- Identify attack paths and assess business risk associated with discovered vulnerabilities.
- Produce detailed technical reports with clear remediation guidance.
- Present findings to clients and participate in remediation discussions.
- Contribute to internal tooling, methodologies, and offensive security research.
- Stay current with emerging attack techniques, vulnerabilities, and offensive security tooling.
- Support and mentor junior consultants where appropriate.
Offensive Security
- Internal Network Assessments
- External Network Assessments
- Active Directory Security Testing
- API Security Testing
- Vulnerability Assessments
- Privilege Escalation
Tools
- Burp Suite Professional
- Nessus
- Nmap
- Wireshark
- BloodHound
- Impacket
Technical Knowledge
- OWASP Top 10
- Web Application Security
- Active Directory
- Windows Security
- Network Security
- Firewalls
- VPN Technologies
- IDS / IPS
- Cloud Security (AWS, Azure or GCP advantageous)
Scripting
Experience with one or more of:
Experience
- 3-5+ years of hands-on penetration testing experience
- Experience working within a consulting or professional services environment advantageous
- Experience conducting multiple concurrent client engagements
- Strong technical report writing skills
- Experience presenting findings directly to clients
Certifications
One or more of the following:
Highly Valued
- OSCP
- CRTP
- CRTE
- CARTP
- PNPT
- PJPT
- eCPPT
- eJPT
Advantageous
Soft Skills
- Strong analytical and troubleshooting abilities
- Professional client communication
- Ability to work independently
- Strong time management
- Collaborative team player
- Continuous learner
Why Join?
- Join one of South Africa’s leading cybersecurity consulting firms.
- Work on varied offensive security engagements across enterprise clients.
- Exposure to modern attack techniques and complex environments.
- Continuous learning and certification support.
- Collaborative team of experienced security professionals.
#J-18808-Ljbffr