Description & Requirements
Key Responsibilities
- Define and scope penetration testing projects for infrastructure, web applications, APIs, and mobile applications.
- Perform regular external/internal infrastructure, web application, API, and mobile penetration tests.
- Provide CLP with detailed reports that contain the necessary insight to support security fixes, patches, remediation, and training to ensure the same opportunities for exploitation do not exist in the future.
- Develop and execute custom scripts to automate and streamline testing procedures.
- Work with development teams and security personnel to help prioritize and remediate identified vulnerabilities.
- Stay current with emerging security threats and vulnerabilities, and share knowledge with other security team members.
- Provide regular reports and assist with creating technical presentations for senior leadership.
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- 4-5 years of experience in penetration testing, vulnerability assessments, and security testing.
- Strong understanding of network security, web application security, API security, and mobile application security. Experience performing both manual and automated penetration testing, using tools such as Burp Suite, Metasploit, and Nmap.
- Knowledge of scripting languages such as Python, Ruby, or PowerShell.
- Excellent written and verbal communication skills, including the ability to gather and critically evaluate information and prepare written documents that clearly and concisely identify the issues presented and their proposed resolution.
- Ability to explain technical issues to non-technical stakeholders.
- Good command of spoken and written English.
- Ability to work collaboratively with cross-functional teams.
- Relevant certifications such as OSCP, or CISSP are a plus.
- Experience with OT-related applications and systems is a plus.
Please apply by clicking "Apply" for application giving a detailed C.V., including academic qualifications, career history, major achievements and personal attributes.
Please input current and expected salary in field of "Sensitive Information" via the application system..
Applicants not invited for interview within 6 weeks from the closing date may assume their applications unsuccessful. Information provided will be for recruitment purpose within the CLP Group and only short-listed candidates will be contacted. We comply with all applicable laws and regulations of HKSAR in handling applications. For details of the Personal Information Collection Statement, please visit our website: https://clp.to/engPICS For further information on our company, please visit our website: https://www.clpgroup.com/