Millennium IT ESP

Senior Engineer – Offensive Security

Millennium IT ESP Colombo, Western Province, Sri Lanka

IT Services and IT Consulting · 201-500 employees

9 h ago
Mid (2-5 yrs) Full-time Sri Lanka
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Conduct comprehensive VAPT and penetration testing across network, web, API, and mobile environments. Prepare detailed technical reports, provide remediation recommendations, and mentor junior security engineers.

What they look for

Vulnerability Assessment Penetration Testing Network Security Web Application Security API Security Mobile Application Security Burp Suite Nmap Metasploit Nessus Kali Linux Python Bash PowerShell OWASP Top 10 Technical Reporting

Requirements

Requires 3+ years of hands-on experience in vulnerability assessment and penetration testing. A degree in a relevant field and professional certifications like OSCP are preferred.

Full description

Job Description 

  • Conduct VAPT and penetration testing across network, web, API and mobile environments
  • Perform both automated and manual security testing to identify and validate vulnerabilities
  • Analyse vulnerabilities, demonstrate their potential impact and provide practical remediation recommendations
  • Prepare clear and professional technical VAPT reports and present findings to clients
  • Develop scripts and use security tools to improve the efficiency of penetration-testing activities
  • Keep up to date with emerging vulnerabilities, exploits and offensive-security techniques
  • Support red-team, security assessment and other offensive-security engagements when required
  • Provide technical guidance and mentoring to junior security engineers

Person Specification

  • Degree in Computer Science, Cybersecurity, Information Security or a related field is preferred
  • 3+ years of hands-on experience in vulnerability assessment, penetration testing (VAPT)
  • OSCP or equivalent offensive-security certification is an advantage
  • Experience in cloud security, red teaming or source-code review will be an added advantage
  • Strong experience in Network, Web Application, API and/or Mobile Application Security Testing
  • Strong understanding of OWASP Top 10 and common security vulnerabilities
  • Hands-on experience with tools such as Burp Suite, Nmap, Metasploit, Nessus/OpenVAS and Kali Linux
  • Good scripting skills in Python, Bash, PowerShell or similar
  • Strong analytical, problem-solving and technical reporting skills
  • Good communication skills with the ability to interact confidently with clients
  • Ability to independently manage VAPT engagements from testing through reporting and client presentation