One of our prestigious international clients is looking for an experienced Offshore Penetration Tester to join their Cyber Security Services team remotely from Sri Lanka.
The successful candidate will act as a lead tester for the delivery of high-quality offensive security and penetration testing services for Australian customers. The role requires strong hands-on capability across internal network, Active Directory, external network and web application penetration testing, together with the ability to identify real-world attack paths, communicate risk clearly and provide practical remediation advice.
SALARY: Negotiable (Based on experience and qualifications)
KEY RESPONSIBILITIES:
- Independently lead authorised penetration testing engagements from planning and scoping through testing, reporting, customer debrief and retesting.
- Conduct hands-on penetration testing across internal network, external network and web application environments.
- Perform Active Directory penetration testing, including enumeration, credential attacks, Kerberos attacks, privilege escalation, lateral movement and attack path development.
- Perform vulnerability discovery, validation and controlled exploitation using manual testing techniques supported by appropriate security testing tools.
- Manually validate vulnerabilities, chain findings where appropriate and explain real-world exploitability and risk.
- Act as the lead tester on engagements involving multiple testers and provide technical direction to junior or developing testers.
- Mentor and upskill onshore Australian testers through shadowing, practical coaching, technical training and knowledge-sharing sessions.
- Help develop and refine penetration testing methodologies, playbooks, checklists, testing standards, report templates and repeatable delivery processes.
- Prepare clear, evidence-based customer-facing penetration testing reports covering findings, risk, impact, supporting evidence and practical remediation recommendations.
- Peer review and quality assure penetration testing findings and reports produced by other testers.
- Present findings to internal stakeholders and support customer-facing technical debriefs in clear, professional English.
- Support retesting activities to validate whether remediation actions have been completed effectively.
- Collaborate with SOC, SIEM, vulnerability management, cloud, network and consulting teams where broader security insight is required.
- Maintain awareness of current vulnerabilities, threat actor behaviours, exploit techniques, security testing tools and defensive controls.
- Operate strictly within customer-approved scope, rules of engagement, legal requirements, confidentiality obligations, evidence-handling requirements, privacy obligations and internal security policies.
REQUIREMENTS:
- Ideally 5+ years of hands-on penetration testing or offensive security experience, with previous senior or lead testing experience preferred.
- Senior-level penetration testing capability with experience delivering complex engagements rather than relying primarily on automated vulnerability assessments.
- Strong hands-on capability across internal network, external network and web application penetration testing.
- Strong Active Directory penetration testing experience, including enumeration, credential attacks, Kerberos attacks, privilege escalation, lateral movement and attack path development.
- Strong understanding of web application, API, network and infrastructure security testing methodologies.
- Experience identifying and exploiting vulnerabilities in web, mobile and API-based applications.
- Red teaming capability, including adversary simulation, lateral movement and privilege escalation in complex environments.
- Practical experience with penetration testing tools and frameworks such as Burp Suite, Metasploit, Nmap, Wireshark and Kali Linux.
- Knowledge of OWASP Top 10, MITRE ATT&CK, common attack paths, vulnerability chaining and risk-based testing approaches.
- Ability to manually validate vulnerabilities and explain real-world exploitability rather than relying solely on automated scanner output.
- Sound understanding of TCP/IP, DNS, VPNs, firewalls, routing, authentication, Active Directory and common enterprise network services.
- Strong penetration testing reporting skills, including clear evidence, risk, impact and remediation recommendations.
- Ability to peer review and quality assure penetration testing reports and findings produced by other testers.
- Strong written and spoken English, with the ability to communicate directly with Australian customers.
- Experience working for a penetration testing consultancy, cyber security professional services organisation or MSSP is highly desirable.
- Experience working in remote or distributed teams with strong time management, structured communication and self-directed work habits.
- High level of integrity, discretion and professionalism when handling sensitive customer information.
- Bachelor’s degree in Computer Science, Information Security or a related field, or equivalent practical experience.
ADDITIONAL SKILLS & CERTIFICATIONS:
- Experience with Azure, Entra ID and Microsoft 365 security will be highly regarded.
- Exposure to AWS, Microsoft Azure or Google Cloud security testing will be advantageous.
- Additional experience in API, mobile application or wireless penetration testing will be an advantage.
- Experience with SIEM and detection platforms such as Microsoft Sentinel, FortiSIEM, Splunk, QRadar or Elastic will be advantageous.
- SOC or incident response experience will be an advantage.
- Application security experience, including secure SDLC, SAST, DAST, source code review and API security testing, will be advantageous.
- Scripting and automation skills using Python, PowerShell, Bash or similar languages will be highly regarded.
- Reverse engineering and malware analysis experience will be advantageous.
- Endpoint, EDR or XDR exposure will be an advantage.
- OT or critical infrastructure security exposure will be advantageous.
- Must hold at least one recognised practical penetration testing certification.
- Preferred certifications include OSCP or CREST CRT/CCT.
- Other relevant certifications such as OSEP, OSWE, PNPT, CPTS, CRTO, GPEN or GWAPT may be considered where supported by strong practical experience.
SOFT SKILLS:
- Curious, methodical and technically hands-on approach, with the ability to think like an attacker while acting responsibly and professionally.
- Senior, self-directed and delivery-focused mindset.
- Strong judgement and ability to lead engagements independently.
- Collaborative approach with a genuine commitment to mentoring, coaching and knowledge sharing.
- Strong attention to detail, particularly when documenting evidence, testing steps, impact and remediation guidance.
- Customer-focused approach with the ability to explain technical risks in clear and practical language.
- Strong written and verbal communication skills.
- Ability to work effectively across offensive security, SOC, SIEM, cloud, network and consulting teams.
- Comfortable working offshore as part of an Australian-led delivery model.
- Ability to maintain structured communication, effective handovers and alignment with Australian business expectations.
- Commitment to continuous learning and staying current with emerging threats, tools, exploit techniques and defensive controls.
BENEFITS:
- Remote working opportunity from Sri Lanka.
- Opportunity to work with an Australian MSSP and Australian customers.
- Exposure to complex international penetration testing and offensive security engagements.
- Opportunity to work across internal network, Active Directory, external network and web application security.
- Direct exposure to senior-level cybersecurity projects and customer environments.
- Opportunity to mentor and collaborate with Australian cyber security professionals.
- Professional development and continuous technical learning opportunities.
- Exposure to broader security functions including SOC, SIEM, cloud security, vulnerability management and security consulting.
TERMS & CONDITIONS:
- Employment Type: Full-time.
- Location: Remote from Sri Lanka.
- Role Type: Offshore Cyber Security.
- Primary Market: Australian customers.
- Experience: Ideally 5+ years of hands-on penetration testing or offensive security experience.
- Senior or lead penetration testing experience preferred.
- Must hold at least one recognised practical penetration testing certification.
- Other terms and conditions apply as per company policy.
If you are interested and meet the above requirements, please forward your detailed CV to:
Call / WhatsApp:
0777 833 575 | 0777 833 576
Office:
0117 387 882 | 0117 387 883
Our Working Hours:
Monday to Friday: 9:30 AM – 5:30 PM
Manpower Lanka Solutions (Pvt) Ltd.
12A, Ridgeway Place, Bambalapitiya, Colombo 04, Sri Lanka
Full-time
Anywhere, Worldwide