Sobre este puesto de Penetration Tester (AEV) en BreachLock
About BreachLock
BreachLock is a fast-growing cybersecurity company focused on modern, scalable, and continuous security testing solutions. We operate at the intersection of offensive security, automation, and cloud-native engineering—building systems that are both resilient and intelligent.
Description
- Work closely with Breach360, a security testing product, to validate and improve the quality, accuracy, and effectiveness of security assessment results.
- Review and validate vulnerabilities, attack paths, evidence, and recommendations generated by the product across Web, Mobile, Infrastructure, Cloud, and other environments.
- Work with clients to understand their environment and objectives, help them interpret Breach360 results, and ensure findings align with their expectations and security requirements.
- Benchmark Breach360's output across different assets, technologies, and scenarios to identify gaps, false positives/negatives, and opportunities for improvement.
- Collaborate with Engineering and Product teams to provide actionable feedback and help improve detection, attack coverage, prioritization, reporting, and overall product capabilities.
- Research new vulnerabilities and attack techniques and develop PoCs, scripts, test cases, or automation to improve the product.
- Recommend practical security testing and remediation approaches from a client and security practitioner perspective.
Requirements
- Degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
- 3+ years of experience in Penetration Testing, Red Teaming, Application Security, or Security Consulting.
- Strong hands-on experience with Web Applications, Infrastructure, Mobile Applications, APIs, and Vulnerability Assessments.
- Strong understanding of tools such as Kali Linux, Burp Suite, Nmap, Metasploit, and other security testing tools.
- Ability to validate automated security findings, identify false positives/negatives, and assess real-world exploitability and impact.
- Experience working with security products, automation, or engineering teams to improve testing capabilities and product output is a strong plus.
- Strong client-facing communication and ability to translate technical findings into practical recommendations.
- Strong analytical, troubleshooting, and research skills with a mindset for continuously improving security testing.
- Programming/scripting experience in Python, .NET, or similar languages.
- Preferred certifications: OSCP, OSCP+, CRTP.
Benefits
- Private Health Insurance