One of our prestigious clients is looking for an experienced Offshore Penetration Tester to join their Cyber Security Services team remotely from Sri Lanka.
The successful candidate will act as a lead tester for the delivery of high-quality offensive security and penetration testing services for Australian customers. The role requires strong hands-on capability across internal network, Active Directory, external network and web application penetration testing, together with the ability to identify real-world attack paths, communicate risk clearly and provide practical remediation advice.
SALARY:
Negotiable (Based on experience and qualifications)
KEY RESPONSIBILITIES:
-
Independently lead authorised penetration testing engagements from planning and scoping through testing, reporting, customer debrief and retesting.
-
Conduct hands-on penetration testing across internal network, external network and web application environments.
-
Perform Active Directory penetration testing, including enumeration, credential attacks, Kerberos attacks, privilege escalation, lateral movement and attack path development.
-
Perform vulnerability discovery, validation and controlled exploitation using manual testing techniques supported by appropriate security testing tools.
-
Manually validate vulnerabilities, chain findings where appropriate and explain real-world exploitability and risk.
-
Act as the lead tester on engagements involving multiple testers and provide technical direction to junior or developing testers.
-
Mentor and upskill onshore Australian testers through shadowing, practical coaching, technical training and knowledge-sharing sessions.
-
Help develop and refine penetration testing methodologies, playbooks, checklists, testing standards, report templates and repeatable delivery processes.
-
Prepare clear, evidence-based customer-facing penetration testing reports covering findings, risk, impact, supporting evidence and practical remediation recommendations.
-
Peer review and quality assure penetration testing findings and reports produced by other testers.
-
Present findings to internal stakeholders and support customer-facing technical debriefs in clear, professional English.
-
Support retesting activities to validate whether remediation actions have been completed effectively.
-
Collaborate with SOC, SIEM, vulnerability management, cloud, network and consulting teams where broader security insight is required.
-
Maintain awareness of current vulnerabilities, threat actor behaviours, exploit techniques, security testing tools and defensive controls.
-
Operate strictly within customer-approved scope, rules of engagement, legal requirements, confidentiality obligations, evidence-handling requirements, privacy obligations and internal security policies.
REQUIREMENTS:
-
Ideally 5+ years of hands-on penetration testing or offensive security experience, with previous senior or lead testing experience preferred.
-
Senior-level penetration testing capability with experience delivering complex engagements rather than relying primarily on automated vulnerability assessments.
-
Strong hands-on capability across internal network, external network and web application penetration testing.
-
Strong Active Directory penetration testing experience, including enumeration, credential attacks, Kerberos attacks, privilege escalation, lateral movement and attack path development.
-
Strong understanding of web application, API, network and infrastructure security testing methodologies.
-
Experience identifying and exploiting vulnerabilities in web, mobile and API-based applications.
-
Red teaming capability, including adversary simulation, lateral movement and privilege escalation in complex environments.
-
Practical experience with penetration testing tools and frameworks such as Burp Suite, Metasploit, Nmap, Wireshark and Kali Linux.
-
Knowledge of OWASP Top 10, MITRE ATT&CK, common attack paths, vulnerability chaining and risk-based testing approaches.
-
Ability to manually validate vulnerabilities and explain real-world exploitability rather than relying solely on automated scanner output.
-
Sound understanding of TCP/IP, DNS, VPNs, firewalls, routing, authentication, Active Directory and common enterprise network services.
-
Strong penetration testing reporting skills, including clear evidence, risk, impact and remediation recommendations.
-
Ability to peer review and quality assure penetration testing reports and findings produced by other testers.
-
Strong written and spoken English, with the ability to communicate directly with Australian customers.
-
Experience working for a penetration testing consultancy, cyber security professional services organisation or MSSP is highly desirable.
-
Experience working in remote or distributed teams with strong time management, structured communication and self-directed work habits.
-
High level of integrity, discretion and professionalism when handling sensitive customer information.
-
Bachelor’s degree in Computer Science, Information Security or a related field, or equivalent practical experience.
ADDITIONAL SKILLS & CERTIFICATIONS:
-
Experience with Azure, Entra ID and Microsoft 365 security will be highly regarded.
-
Exposure to AWS, Microsoft Azure or Google Cloud security testing will be advantageous.
-
Additional experience in API, mobile application or wireless penetration testing will be an advantage.
-
Experience with SIEM and detection platforms such as Microsoft Sentinel, FortiSIEM, Splunk, QRadar or Elastic will be advantageous.
-
SOC or incident response experience will be an advantage.
-
Application security experience, including secure SDLC, SAST, DAST, source code review and API security testing, will be advantageous.
-
Scripting and automation skills using Python, PowerShell, Bash or similar languages will be highly regarded.
-
Reverse engineering and malware analysis experience will be advantageous.
-
Endpoint, EDR or XDR exposure will be an advantage.
-
OT or critical infrastructure security exposure will be advantageous.
-
Must hold at least one recognised practical penetration testing certification.
-
Preferred certifications include OSCP or CREST CRT/CCT.
-
Other relevant certifications such as OSEP, OSWE, PNPT, CPTS, CRTO, GPEN or GWAPT may be considered where supported by strong practical experience.
SOFT SKILLS:
-
Curious, methodical and technically hands-on approach, with the ability to think like an attacker while acting responsibly and professionally.
-
Senior, self-directed and delivery-focused mindset.
-
Strong judgement and ability to lead engagements independently.
-
Collaborative approach with a genuine commitment to mentoring, coaching and knowledge sharing.
-
Strong attention to detail, particularly when documenting evidence, testing steps, impact and remediation guidance.
-
Customer-focused approach with the ability to explain technical risks in clear and practical language.
-
Strong written and verbal communication skills.
-
Ability to work effectively across offensive security, SOC, SIEM, cloud, network and consulting teams.
-
Comfortable working remotely as part of an Australian-led delivery model.
-
Ability to maintain structured communication, effective handovers and alignment with Australian business expectations.
-
Commitment to continuous learning and staying current with emerging threats, tools, exploit techniques and defensive controls.
BENEFITS:
-
Remote working opportunity from Sri Lanka.
-
Opportunity to work with an Australian MSSP and Australian customers.
-
Exposure to complex international penetration testing and offensive security engagements.
-
Opportunity to work across internal network, Active Directory, external network and web application security.
-
Direct exposure to senior-level cybersecurity projects and customer environments.
-
Opportunity to mentor and collaborate with Australian cyber security professionals.
-
Professional development and continuous technical learning opportunities.
-
Exposure to broader security functions including SOC, SIEM, cloud security, vulnerability management and security consulting.
TERMS & CONDITIONS:
-
Employment Type: Full-time.
-
Location: Remote from Sri Lanka.
-
Recruitment Type: Local Recruitment.
-
Role Type: Offshore Cyber Security.
-
Primary Market: Australian customers.
-
Experience: Ideally 5+ years of hands-on penetration testing or offensive security experience.
-
Senior or lead penetration testing experience preferred.
-
Must hold at least one recognised practical penetration testing certification.
-
Other terms and conditions apply as per company policy.
HOW TO APPLY:
If you are interested and meet the above requirements, please forward your detailed CV to:
Email your CV to:
This email address is being protected from spambots. You need JavaScript enabled to view it.
Call / WhatsApp:
0777 833 575 | 0777 833 576
Office:
0117 387 882 | 0117 387 883
Our Working Hours:
Monday to Friday: 9:30 AM – 5:30 PM
Manpower Lanka Solutions (Pvt) Ltd.
12A, Ridgeway Place, Bambalapitiya, Colombo 04, Sri Lanka.











