Description
Job Summary:
We are seeking a Pentester / Bug Bounty Researcher with experience in offensive application and enterprise environment assessments for offensive security and penetration testing projects.
Key Highlights:
1. Experience in Pentesting, Bug Bounty, or Red Team.
2. Solid knowledge of Web Application Security and APIs.
3. Analytical thinking to discover complex vulnerabilities.
Vacancy | Pentester / Bug Bounty Researcher — Remote
We are looking to hire a Pentester / Bug Bounty Researcher with experience in offensive assessment of applications and enterprise technology environments. The selected professional will participate in offensive security and penetration testing projects targeting local enterprise infrastructures, primarily focusing on web applications and platforms within authorized scopes.
**Responsibilities**
**\- Execute the full reconnaissance, enumeration, and analysis process for the assigned scope.**
**\- Deeply understand the architecture, functional flows, and operational logic of the evaluated platforms.**
**\- Identify web application vulnerabilities following OWASP methodologies and best practices, as well as vulnerabilities associated with underlying technologies.**
**\- Detect and responsibly exploit business logic vulnerabilities and design flaws.**
**\- Assess the security of cloud infrastructure, servers, databases, APIs, and other authorized assets within each project's scope.**
**\- Identify opportunities for vulnerability chaining to demonstrate higher-impact exploitation scenarios.**
**\- Use offensive security tools such as Nmap, Burp Suite, Caido, SQLmap, Nikto, among others.**
**\- Develop clear and reproducible PoCs (Proofs of Concept) to validate findings.**
**\- Produce detailed technical reports including evidence, impact, exploitation methodology, reproduction steps, and remediation recommendations.**
**\- Work autonomously, organizedly, and disciplinedly, maintaining a rigorous methodology throughout each assessment.**
Ideal Candidate Profile
\- Practical experience in Pentesting, Bug Bounty, or Red Team.
\- Solid knowledge of Web Application Security, APIs, authentication, authorization, session management, and business logic. \- Ability to perform technical reconnaissance and analysis without relying solely on automated tools. \- Ability to quickly understand unfamiliar architectures and technologies.
\- Analytical thinking to uncover complex vulnerabilities and construct attack chains.
\- Excellent technical documentation and communication skills.
\- High level of autonomy, responsibility, and attention to detail.
**Remote Work | Enterprise Projects | Offensive Security**
**All work will be conducted exclusively on pre-authorized and scope-defined assets and systems for each assessment.**
**If you have experience identifying vulnerabilities beyond scanner results and enjoy understanding how applications truly work to uncover high-impact scenarios, we want to meet you.**
Apply by submitting your CV and, if available, links to Bug Bounty profiles, write-ups, GitHub repositories, or relevant certifications.
Work Location: Remote employment