18/09/2020
Position: Pe*******on Tester
Experience: 2 + Years
Job Location: Goa
Source IT Out (SIO) is a fast-growing technology-based Global Outsourcing Company with a large base of international clients. Headquartered in the capital city of Goa in Panaji and other branch offices in Kochi & UK. We offer a vast range of services from Highly Technical Expertise to Creative and Essential services like Digital Marketing, Finance, Operations & Customer Support Solutions.
If you are the kind of individual with unrecognized talent and hunger who will willing to learn and push the envelope, SIO is the right company for you.
Duties and Responsibilities:
• Perform security tests on networks, web-based applications, and computer systems.
• Design these tests and tools to try to break into security-protected applications and networks to probe for vulnerabilities.
• Conduct physical assessments of servers, systems, and network device security. They look for ways to exploit vulnerabilities and design solutions to security issues like temperature, humidity, vandalism, and natural disasters.
• Conduct Security Audits to pinpoint ways that attackers could exploit weaknesses in security systems by conducting network and system security audit
• Analyze organization enforced policies for effectiveness, suggest improvements on security policies, and work to enhance methodology material.
• Write Security Assessment Reports and discuss solutions with IT teams and management.
• Stay up to date with the latest methods for ethical hacking and testing and keep evaluating new pe*******on testing tools.
• Perform pe*******on testing, complying with NIST SP 800-115; produce reports and conduct management briefings on test activities, scenarios, results and recommendations
• Stay abreast of current attack vectors and unique methods for exploitation of computer networks.
• Render expertise and guidance to other cyber security programs regarding intrusion methods
Skills
• Exceptional ability to operate vulnerability scanners such as Nessus and Nexpose
• Strong technical proficiency in all major operating systems, especially Linux and Windows
• Able to hack into web applications that are vulnerable to attacks such as SQL injection and command ex*****on
• Able to gain domain administrator on a Windows domain remotely if provided a working system level exploit on a test environment
• Able to perform chained attacks, privilege escalation, and lateral movement techniques
• Able to assess the security of communication and data storage used in mobile applications
• Ability to operate Metasploit, Burp Suite, crackmapexec, nmap, Wireshark, Metasploit, Hydra, John and many other hacking tools
• Proficiency reading and writing shell scripts
• Ability to extract user password hashes and operate hashcat in a proficient manner
• Proficiency in networking and routing concepts
• Expertise in creating phishing campaigns and performing physical social engineering to obtain system and building access as well as to gather critical documents and information
• Deep understanding of 3-tiered Web Application and Mobile Application Architectures
• Manual Pe*******on Testing Experience (i.e. mapping applications, injecting SQLi, XSS, XXE, exploit creation)
Education:
Bachelor/Diploma in IT or Equivalent
Must- CEH certification/Crest
Advantageous IT Security Certifications such as: Security+, CYSA+, CISA, CISSP, OSCP, QSA, GWAPT
BENEFITS
• Exposure to working with various clients and different industries
• Vibrant co-working area, with weekend employee engagement activities.
• Common Lounge within house tea/coffee vending machine.
• Entitle to Indian and U.K holidays
Working Days-Monday to Friday
Saturday and Sunday-weekly off
Job Timings- 1.30 to 10.30 pm