Job Overview:
We are seeking a skilled Penetration Tester with strong expertise in cybersecurity assessment, vulnerability management, and security tools such as Qualys, Nessus, Burp Suite, Metasploit, and more. The ideal candidate will be responsible for conducting security assessments, ethical hacking, and penetration testing to identify and remediate vulnerabilities in networks, applications, and cloud environments.
Key Responsibilities:
- Perform penetration testing on web applications, networks, cloud infrastructure, APIs, and mobile applications.
- Utilize Qualys, Nessus, Burp Suite, Metasploit, and other security tools to identify and remediate security vulnerabilities.
- Conduct vulnerability assessments, exploit research, and security audits to assess and enhance system defenses.
- Develop detailed security assessment reports and provide actionable recommendations to stakeholders.
- Work with DevOps and security teams to implement secure coding best practices and risk mitigation strategies.
- Simulate real-world cyberattacks and assess the effectiveness of security controls.
- Stay updated with the latest security threats, vulnerabilities, and industry best practices.
- Support security compliance initiatives, including NIST, ISO 27001, CIS, and SOC 2 requirements.
Required Skills & Qualifications:
- 3-5+ years of experience in penetration testing, red teaming, and ethical hacking.
- Hands-on experience with Qualys, Nessus, Burp Suite, Metasploit, Kali Linux, and other security tools.
- Strong understanding of network security, cloud security (AWS, Azure, GCP), and application security.
- Proficiency in scripting languages like Python, PowerShell, Bash, or JavaScript to develop custom security tools.
- Deep knowledge of OWASP Top 10, MITRE ATT&CK framework, CVSS scoring, and security frameworks.
- Experience with secure coding practices, web application firewalls (WAF), and intrusion detection systems (IDS).
- Certifications preferred: CEH, OSCP, GPEN, CISSP, or equivalent.
Nice to Have:
- Experience with cloud security testing in AWS, Azure, or GCP.
- Knowledge of Zero Trust security models and threat intelligence platforms.
- Familiarity with DevSecOps integration and automated security testing.
This is a remote position.
Mission Statement
Softthink Solutions’ mission is to drive continuous innovation in IT services by prioritizing product development and implementing trustworthy computing practices. Our focus on secure and reliable product delivery is backed by sound business practices and a commitment to the long-term satisfaction of our clients in every project, regardless of its size or complexity.
Through our innovative solutions and dedicated team of experts, we strive to exceed our clients’ expectations and set the standard for excellence in the IT industry.
Vision Statement
At Softthink Solutions, our vision is to be a trusted partner for our clients, empowering them to bring their ideas to life in the most efficient and effective manner possible. We are committed to using established best practices, industry-standard processes, and cutting-edge technology to deliver top-notch solutions that exceed expectations.
Our goal is to be recognized as leaders in the industry for our innovative, reliable, and secure IT services and solutions, and to drive the success of our clients through every project we undertake.
Careers
STSI is an independent US-based Software services and consulting partner with a primary focus on long-term relationships with both clients and team members.
STSI offers team members cutting-edge technology, training, and career guidance to expand and grow their skill sets and bring maximum value to our clients.
STSI is constantly reviewing and expanding its people strength and strives to optimally match client needs to team member talents. We are a people-oriented company seeking the best and brightest to join our team. We work with a variety of employment statuses – from citizens to permanent residents to H1B and EAD immigrants. We have openings for entry level as well as senior positions across a variety of specializations with active in-house and client projects.
In an industry that’s constantly reinventing itself, STSI challenges its team members and consultants with engagements that involve specialized services and advanced IT solutions – applying agile development principles, methodical planning, creative thinking, and continuous learning. A dynamic environment keeps our team members ahead of the curve by providing:
In an industry that’s constantly reinventing itself, STSI challenges its team members and consultants with engagements that involve specialized services and advanced IT solutions – applying agile development principles, methodical planning, creative thinking, and continuous learning. A dynamic environment keeps our team members ahead of the curve by providing:
- Opportunities to work with leading multinational clients.
- A comprehensive portfolio of solutions that span leading-edge technologies from Enterprise Architecture to Business Intelligence to Quality Assurance
- Established methodologies, processes, and mentoring to maximize efficacy and efficiency.
- A growing R&D division continually exploring and pioneering the latest technological developments in a variety of disciplines.
(if you already have a resume on Indeed)