Penetration Tester

Security & Risk
Full Time
Intermediate (1-3 years)
Published on 14/09/2026
Fully Remote
Malta

Job Description

Overview

Are you passionate about offensive security and enjoy uncovering vulnerabilities before attackers do? Do you thrive on solving complex security challenges and helping organisations strengthen their defences? If so, CyberSift is looking for a motivated and hands-on Penetration Tester to join our growing cybersecurity team.

In this role, you will conduct security assessments across web applications, APIs, and mobile applications, helping clients identify and remediate vulnerabilities before they can be exploited. You'll work independently to manage engagements from initial client communication through to final reporting, delivering valuable security insights that make a real impact.

Who You Are

  • Hands-On Experience: At least 1 year of practical experience testing web applications, APIs, and mobile applications.
  • Demonstrable Skills: Experience may have been gained through professional penetration testing engagements, bug bounty programs, Hack The Box, TryHackMe, personal labs, security research, or similar hands-on environments.
  • Technical Expertise: Strong understanding of common vulnerabilities, attack methodologies, and penetration testing techniques for web, API, and mobile environments.
  • Testing Methodology: Ability to independently plan, execute, validate findings, and complete a penetration test engagement from start to finish.
  • Communication Skills: Excellent written and verbal communication skills, with the ability to translate technical findings into clear, actionable recommendations.
  • Reporting Skills: Experience producing professional penetration testing reports for technical and non-technical audiences.
  • Passion for Security: A strong interest in application security, emerging attack techniques, and continuous learning within the cybersecurity field.
  • Self-Motivation: Comfortable working independently, managing multiple priorities, and taking ownership of engagements.
  • Certifications: At least one practical, hands-on penetration testing certification such as OSCP, OSWA, OSWE, HTB CWES, HTB CWEE, or an equivalent certification.

What You'll Do

As a Penetration Tester, you will play a critical role in helping our clients identify and address security weaknesses across their applications and systems. Your responsibilities will include:

  • Security Assessments: Perform penetration tests against web applications, APIs, and mobile applications using a structured and repeatable methodology.
  • Client Engagement: Communicate directly with clients throughout engagements, ensuring clear expectations, timely updates, and professional delivery of services.
  • Vulnerability Validation: Identify, verify, and assess security vulnerabilities, evaluating their potential business impact and exploitability.
  • Reporting: Produce detailed, professional, and actionable penetration testing reports that clearly communicate findings and remediation recommendations.
  • Technical Research: Stay current with emerging vulnerabilities, attack techniques, security trends, and industry best practices.
  • Continuous Improvement: Contribute to the development and enhancement of testing methodologies, tools, and internal knowledge-sharing initiatives.
  • Advisory Support: Assist clients in understanding findings and provide guidance on remediation efforts when needed.

Who We Are

At CyberSift, we are committed to helping organisations strengthen their security posture through expert-led cybersecurity services and innovative security solutions.

Our team consists of passionate cybersecurity professionals who thrive on solving real-world challenges and staying ahead of the evolving threat landscape. We foster a culture of collaboration, continuous learning, and technical excellence, empowering our people to develop their skills while making a meaningful impact for our clients.

Why CyberSift?

  • Generous remuneration
  • Flexible hybrid/remote work setup
  • Opportunities for career growth and professional development
  • Support for industry certifications and continuous learning
  • Access to cutting-edge security tools, platforms, and technologies
  • Exposure to diverse and challenging security engagements
  • Organisational culture that values autonomy, transparency, and employee growth