About the role
As a Penetration Tester at Vorpcel, you will conduct authorized offensive security assessments across web and mobile applications, APIs, internal and external networks, cloud environments and wireless infrastructure. Social engineering may also be part of an engagement when it is explicitly authorized.
You will combine disciplined methodology with creative manual testing to uncover issues that automated tools miss, connect individual weaknesses into realistic attack paths and demonstrate their technical and business impact safely.
Your work will give customers clear evidence, practical remediation guidance and confidence that fixes are effective. It will also help Vorpcel improve its products, research and understanding of how attacks behave in real environments.
What you will do
- Plan, scope and execute authorized penetration tests with clear rules of engagement.
- Assess web applications, APIs, mobile applications, networks, cloud services and wireless environments.
- Perform manual reconnaissance, exploitation, privilege escalation and lateral movement where authorized.
- Validate vulnerabilities safely and connect related findings into realistic attack paths.
- Document reproducible evidence, affected assets, impact and practical remediation guidance.
- Communicate risk clearly to engineers, security teams and business leaders.
- Retest remediated findings and verify that fixes address the underlying weakness.
- Improve internal testing methods, tooling, checklists and knowledge sharing.
- Track emerging vulnerabilities, exploitation techniques and changes in offensive tooling.
- Protect customer data and operate with strict ethics, discretion and respect for scope.
What we look for
- Demonstrated hands-on penetration testing experience across more than one technical domain.
- Strong knowledge of web, API and network attack classes, including the OWASP Top 10.
- Ability to perform manual exploitation and validate impact without relying only on scanners.
- Practical experience with tools such as Burp Suite, Nmap, Metasploit or equivalent tooling.
- Ability to automate tasks or build testing utilities with Python, Go or Bash.
- Working knowledge of authentication, Active Directory, containers and common cloud platforms.
- Clear technical writing with accurate reproduction steps and prioritized remediation.
- Sound judgment, strong ethics and disciplined adherence to authorization and scope.
- Nice to have: experience with mobile, wireless or social-engineering assessments.
- Nice to have: OSCP, OSWE, OSEP, GPEN or equivalent evidence such as research, CVEs or CTF results.