Loading open roles
Loading open roles
Loading role

Job Description – Infrastructure Penetration Tester
Experience
• 2 to 4 years of relevant work experience in Infrastructure Penetration Testing , Network Security Assessments, Red Teaming, or related areas
Core Responsibilities
• Conduct
infrastructure penetration testing
across
internal networks, external network perimeters, cloud environments, and
hybrid infrastructures
• Perform
network, server, and system‑level security assessments
including on‑prem, cloud (AWS/Azure/GCP), and virtualization platforms
• Identify vulnerabilities, misconfigurations, weak authentication mechanisms,
insecure protocols, and privilege escalation paths
• Perform
Active Directory security assessments
including Kerberos attacks, NTLM abuse, delegation issues, lateral movement,
and domain persistence techniques
• Execute
external and internal network assessments
, VPN testing, firewall rule reviews, and segmentation testing
• Conduct
configuration review
for operating systems, servers, devices, and security controls
• Validate security of
identity and access management (IAM)
, authentication, authorization, password policies, and privilege models
• Perform
post‑exploitation activities
such as pivoting, credential harvesting, lateral movement, and data
exfiltration simulations
• Prepare
detailed penetration testing reports
including risk rating, impact analysis, proof‑of‑concept, and remediation
guidance
• Communicate findings clearly to technical and non‑technical stakeholders
Technical Skill Requirements
Infrastructure & Network Knowledge
• Strong understanding of
networking concepts
: TCP/IP, DNS, DHCP, SMTP, HTTP/S, SNMP, VPNs, firewalls, IDS/IPS
• Thorough understanding of
enterprise infrastructure architectures
• Hands‑on experience with
Windows, Linux, and Unix operating systems
• Knowledge of
security standards, frameworks, and methodologies
(OWASP, MITRE ATT&CK, NIST, ISO 27001, PTES)
Attack Techniques & Assessment Areas
• Network service enumeration and exploitation
• Privilege escalation (Linux & Windows)
• Active Directory attacks (Pass‑the‑Hash, Kerberoasting, Golden/Silver
Tickets, ACL abuse, DCSync)
• Password attacks (offline/online cracking, spraying)
• Misconfiguration and patch management testing
• Remote access and VPN security testing
• Cloud infrastructure security testing (IAM misconfigs, exposed services,
storage permissions)
• Enumeration, lateral movement, and persistence techniques
Tools & Platforms
• Proficient with leading infrastructure testing tools including:
–
Nmap, Nessus, Qualys
–
Metasploit, CrackMapExec, BloodHound, Mimikatz
–
Burp Suite (basic for infra portals / VPN portals)
–
Kali Linux
and other attack platforms
• Familiarity with
EDR, SIEM, and logging controls
is a plus
Soft Skills
• Strong
communication and presentation skills
• Ability to explain complex infrastructure risks to varied audiences
• Experience working with SOC, IT Infrastructure, and Blue Teams
• Strong documentation and reporting capability
Preferred Qualifications (Good to have)
• Industry‑recognized certifications such as:
–
OSCP, OSCE, CRTP, CRTE, CRTO, GPEN, GWAPT, PNPT
(any relevant infra‑focused certification)
•
CVE contributors, red‑team practitioners
preferred
• Exposure to
Purple Team exercises
and security validation engagements is a plus