Penetration Tester - South Africa (Remote)
Location: South Africa (Remote)
Salary: R400 000 - R550 000 per annum (DOE)
About Cognisys
Are you ready to make an impact in the fast-paced world of cybersecurity? Cognisys is growing rapidly, and we’re looking for a Penetration Tester to join our team during this exciting period of innovation and expansion.
Cognisys is a leading cybersecurity company specialising in Penetration Testing, GRC Consulting and Managed Security Services. We pride ourselves on our customer service, forward-thinking approach and commitment to excellence. Our small but mighty team works with some of the best-known companies in the world and supports clients across more than 30 countries.
The Opportunity
As a Pen Tester, you will play a key role in delivering high-quality security assessments for our clients. You will test a range of environments, including networks, web applications, APIs, mobile applications and cloud infrastructure, using a combination of automated tools and manual testing techniques.
This is an opportunity to work on varied and challenging engagements, collaborate with experienced cybersecurity professionals and work directly with clients to help them understand and improve their security posture.
What You'll Be Doing
As a Penetration Tester, you will:
Conduct penetration testing across network, web application, API, mobile application and cloud environments.
Simulate real-world attack scenarios to assess clients' resilience against cyber threats.
Use a combination of automated tools, manual testing and exploitation techniques to identify and validate vulnerabilities.
Assess technical security controls and identify potential weaknesses and attack paths.
Analyse vulnerabilities and assess their potential business and security impact.
Produce high-quality technical reports outlining vulnerabilities, associated risks and practical remediation recommendations.
Clearly communicate complex technical findings in a way that can be understood by both technical and non-technical stakeholders.
Present findings and recommendations directly to clients, helping them understand, prioritise and remediate identified vulnerabilities.
Work collaboratively with colleagues to ensure the successful delivery of client engagements.
Keep up to date with emerging threats, vulnerabilities, tools and offensive security techniques.
Contribute to the continued development and improvement of Cognisys' penetration testing capabilities and methodologies.
What Success Looks Like
In your first few months, success in this role will look like:
Building a strong understanding of Cognisys' services, methodologies and approach to client delivery.
Successfully delivering penetration testing engagements to a high standard.
Producing clear, accurate and high-quality reports that provide clients with meaningful and actionable recommendations.
Building strong relationships with clients and communicating confidently throughout engagements.
Demonstrating sound technical judgement when identifying, validating and assessing vulnerabilities.
Effectively managing your time and workload across multiple engagements and competing priorities.
Continuously developing your technical knowledge and keeping up to date with developments in the offensive security landscape.
Contributing ideas and expertise to help improve our tools, methodologies and ways of working.
About You
We're looking for a passionate and technically capable penetration tester who enjoys understanding how systems work, identifying weaknesses and thinking creatively about how security controls could be bypassed.
You'll be someone who is naturally curious, enjoys solving complex problems and is motivated by staying ahead of emerging threats and attack techniques.
We’re also looking for someone who can combine strong technical capability with excellent client communication. You should be comfortable explaining complex vulnerabilities clearly, presenting your findings and helping clients understand the practical steps they can take to improve their security.
You'll thrive in this role if you enjoy variety, working across different technologies and environments, collaborating with others and continuously developing your technical skills.
Essential Skills & Experience
Hands-on experience conducting penetration testing across one or more areas, including networks, web applications, APIs, mobile applications or cloud environments.
Strong understanding of offensive security methodologies, tools and techniques.
Experience using vulnerability scanning tools alongside manual testing and exploitation techniques.
Strong grasp of how to assess and break technical controls and identify potential attack paths.
Experience identifying, analysing and validating security vulnerabilities.
Ability to assess the potential impact and risk associated with identified vulnerabilities.
Experience producing high-quality penetration testing reports with clear and practical remediation recommendations.
Ability to communicate complex technical findings clearly to both technical and non-technical audiences.
Strong written and verbal communication skills.
Excellent client engagement skills and confidence presenting technical findings and recommendations.
Ability to manage multiple engagements, priorities and deadlines effectively.
A proactive approach to problem-solving and continuous learning.
Desirable Skills & Experience
Industry-recognised certifications such as CPSA, CRT, OSCP or similar.
Experience testing a broad range of technologies and environments.
Experience working within a cybersecurity consultancy or professional services environment.
Experience presenting penetration testing findings directly to clients.
Knowledge of emerging cybersecurity threats, attack techniques and offensive security tools.
Experience with cloud security assessments across platforms such as AWS, Azure or GCP.
Experience with API and mobile application security testing.
Certifications
Industry-recognised penetration testing or offensive security certifications are highly desirable, including:
OSCP – Offensive Security Certified Professional
CPSA – CREST Practitioner Security Analyst
CRT – CREST Registered Tester
CREST CPSA/CRT equivalent certifications
Other recognised offensive security or penetration testing certifications will also be considered.
We value practical technical capability and hands-on experience alongside certifications, so candidates with strong relevant experience who are working towards certification are also encouraged to apply.
Why Join Us?
At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact for our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged.
What we Offer:
Annual Leave: 25 days per year plus 12 South African public holidays.
Additional Leave: 1 day of paid leave for your Birthday.
Health & Wellbeing: Individual healthcare insurance plan and access to an employee mental health and wellbeing platform.
Professional Development: £2,000 annual training budget to support your continued learning and career growth.
Referral Bonus: help to grow our team and earn up to £2,000 per successful referral.
Applications
We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page.
Please feel free to reach out to Andrea, our Talent Acquisition Lead, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.co.uk
We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.
- Department
- Tech Team
- Role
- Security Consultant
- Locations
- South Africa
- Remote status
- Fully Remote