As a Junior Security Consultant at TÜV SÜD, you will perform black-box and grey-box penetration testing on critical applications and infrastructure. Your role involves identifying and exploiting vulnerabilities across diverse environments, conducting external attack surface assessments, and simulating real-world attack scenarios to identify perimeter weaknesses. You will be responsible for delivering detailed reports featuring risk ratings, CVSS 4.0 scores , and actionable remediation guidance.
You will specialize in Web Application Testing and Mobile Security Testing (Android/iOS), performing both static and dynamic test cases. Following the OWASP Top 10 framework, you will conduct manual and automated testing using industry-standard tools. Additionally, you will develop system hardening baselines and collaborate with development teams to remediate security gaps, ensuring that our clients maintain a robust compliance posture against the latest exploits and trends.
Key Responsibilities
Perform black-box and grey-box penetration testing on apps and infra.
Conduct external attack surface assessments and network service testing.
Simulate real-world attacks to identify and validate perimeter weaknesses.
Deliver comprehensive reports with CVSS 4.0 scoring and Proof of Concepts (PoCs).
Perform Android and iOS security testing (Static & Dynamic).
Identify vulnerabilities based on the OWASP Top 10 vulnerabilities list.
Develop and review system hardening baselines for various environments.
Collaborate with developers to guide them through vulnerability remediation.
Stay updated with the latest cybersecurity trends, exploits, and zero-day threats.
Skills & Eligibility
Education: Graduate in Electronics Engineering or Computer Science.
Experience: 1-2 years of relevant experience in security consulting/pen-testing.