Penetration Tester (Colombia)

Penetration Tester (Colombia)

24 sep
|
Bright
|
Colombia

24 sep

Bright

Colombia

Penetration Tester

Company Description

Bright Security delivers an enterprise-grade, developer-centric DAST platform that helps organizations identify and remediate vulnerabilities early and continuously in the SDLC. The platform is widely used for security testing of web applications, APIs, business logic, and LLM-based solutions.

By integrating security testing into development workflows, Bright enables security and engineering teams to identify vulnerabilities earlier, improve collaboration, and accelerate remediation.

Role Description

This is a full-time, remote role for a Penetration Tester based in Colombia.

The Penetration Tester will independently perform detailed security assessments of web applications, APIs, business logic, and other modern application environments using manual and automated techniques.

The role requires a strong focus on quality, thoroughness, creativity, and depth of testing. We are looking for someone who goes beyond automated scanner results, actively investigates application behavior, explores attack paths, and identifies vulnerabilities through reasoning and manual analysis.

The successful candidate should understand the full penetration testing lifecycle, including scoping, testing, exploitation and validation, evidence collection, risk assessment, reporting, remediation guidance, and retesting.

Key responsibilities include

- Performing thorough manual and automated penetration testing of web applications and APIs.
- Independently planning and executing assigned assessments with minimal supervision.
- Testing authentication, authorization, session management, access control, business logic, input handling, and API behavior.
- Identifying vulnerabilities through manual investigation, creative testing, and analysis beyond automated scanner output.




- Developing and validating practical proof-of-concept exploitation where appropriate.
- Producing clear, detailed, customer-ready penetration testing findings and reports.
- Providing practical remediation guidance and validating fixes through retesting.
- Contributing to testing methodologies, tooling, knowledge sharing, and continuous improvement.
- Supporting additional testing areas such as cloud, mobile, red team, and AI or LLM security depending on experience.

Qualifications
- Demonstrable hands-on experience with penetration testing, vulnerability research, bug hunting, bug bounty work, or comparable offensive security activities.
- Strong practical knowledge of web and API security, including OWASP Top 10, OWASP API Security Top 10, authentication, authorization, access control, and business logic vulnerabilities.
- Ability to perform meaningful manual testing rather than relying primarily on automated tools.
- Strong investigative mindset, attention to detail, and ability to identify non-obvious attack paths.
- Understanding of the complete penetration testing process, including methodology, evidence collection, validation, reporting, and retesting.
- Ability to work independently with little day-to-day handholding.
- Experience producing professional penetration testing reports with clear reproduction steps, impact, evidence, and remediation guidance.
- Very good to excellent written and spoken English,



including customer-facing technical communication.
- Familiarity with tools such as Burp Suite, Nmap, Postman, browser developer tools, and relevant command-line tooling.
- Good understanding of HTTP, APIs, modern web architectures, networking, operating systems, authentication, and access control.
- Ability to use scripting or programming languages such as Python, JavaScript, Bash, or similar languages.

Advantageous Experience The following are beneficial but not required:
- Approximately 2 to 4 years of professional penetration testing, application security, or offensive security experience.
- Experience testing complex APIs, multi-tenant applications, authorization models, and business logic.
- Bug bounty participation or independently discovered vulnerabilities.
- Experience with cloud, mobile, network penetration testing, red team, or AI and LLM application security.
- Familiarity with DAST, SAST, CI/CD security testing, or DevSecOps environments.
- Relevant offensive security certifications.

Skills Over Certifications Certifications such as OSCP, OSWE, CPTS, PNPT, GWAPT, GPEN, or eWPT are welcome but not required and will not substitute for practical ability.

Bright places greater value on demonstrated testing skill, depth, thoroughness, creativity, independence, reporting quality, and professional judgment.

Practical Assessment

Candidates progressing through the process will complete a hands-on penetration testing assessment against an authorized target selected by Bright Security.

- The assessment will evaluate practical testing ability, methodology, coverage, vulnerability identification and validation, depth of investigation, quality of evidence, reporting, and the ability to clearly explain findings and remediation recommendations.

📌 Penetration Tester (Colombia)
🏢 Bright
📍 Colombia

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: penetration tester (colombia) / colombia

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: penetration tester (colombia) / colombia