One of our prestigious clients is looking for an experienced Offshore Penetration Tester to join their Cyber Security Services team remotely from Sri Lanka.

The successful candidate will act as a lead tester for the delivery of high-quality offensive security and penetration testing services for Australian customers. The role requires strong hands-on capability across internal network, Active Directory, external network and web application penetration testing, together with the ability to identify real-world attack paths, communicate risk clearly and provide practical remediation advice.


SALARY:

Negotiable (Based on experience and qualifications)


KEY RESPONSIBILITIES:

  • Independently lead authorised penetration testing engagements from planning and scoping through testing, reporting, customer debrief and retesting.

  • Conduct hands-on penetration testing across internal network, external network and web application environments.

  • Perform Active Directory penetration testing, including enumeration, credential attacks, Kerberos attacks, privilege escalation, lateral movement and attack path development.

  • Perform vulnerability discovery, validation and controlled exploitation using manual testing techniques supported by appropriate security testing tools.

  • Manually validate vulnerabilities, chain findings where appropriate and explain real-world exploitability and risk.

  • Act as the lead tester on engagements involving multiple testers and provide technical direction to junior or developing testers.

  • Mentor and upskill onshore Australian testers through shadowing, practical coaching, technical training and knowledge-sharing sessions.

  • Help develop and refine penetration testing methodologies, playbooks, checklists, testing standards, report templates and repeatable delivery processes.

  • Prepare clear, evidence-based customer-facing penetration testing reports covering findings, risk, impact, supporting evidence and practical remediation recommendations.

  • Peer review and quality assure penetration testing findings and reports produced by other testers.

  • Present findings to internal stakeholders and support customer-facing technical debriefs in clear, professional English.

  • Support retesting activities to validate whether remediation actions have been completed effectively.

  • Collaborate with SOC, SIEM, vulnerability management, cloud, network and consulting teams where broader security insight is required.

  • Maintain awareness of current vulnerabilities, threat actor behaviours, exploit techniques, security testing tools and defensive controls.

  • Operate strictly within customer-approved scope, rules of engagement, legal requirements, confidentiality obligations, evidence-handling requirements, privacy obligations and internal security policies.


REQUIREMENTS:

  • Ideally 5+ years of hands-on penetration testing or offensive security experience, with previous senior or lead testing experience preferred.

  • Senior-level penetration testing capability with experience delivering complex engagements rather than relying primarily on automated vulnerability assessments.

  • Strong hands-on capability across internal network, external network and web application penetration testing.

  • Strong Active Directory penetration testing experience, including enumeration, credential attacks, Kerberos attacks, privilege escalation, lateral movement and attack path development.

  • Strong understanding of web application, API, network and infrastructure security testing methodologies.

  • Experience identifying and exploiting vulnerabilities in web, mobile and API-based applications.

  • Red teaming capability, including adversary simulation, lateral movement and privilege escalation in complex environments.

  • Practical experience with penetration testing tools and frameworks such as Burp Suite, Metasploit, Nmap, Wireshark and Kali Linux.

  • Knowledge of OWASP Top 10, MITRE ATT&CK, common attack paths, vulnerability chaining and risk-based testing approaches.

  • Ability to manually validate vulnerabilities and explain real-world exploitability rather than relying solely on automated scanner output.

  • Sound understanding of TCP/IP, DNS, VPNs, firewalls, routing, authentication, Active Directory and common enterprise network services.

  • Strong penetration testing reporting skills, including clear evidence, risk, impact and remediation recommendations.

  • Ability to peer review and quality assure penetration testing reports and findings produced by other testers.

  • Strong written and spoken English, with the ability to communicate directly with Australian customers.

  • Experience working for a penetration testing consultancy, cyber security professional services organisation or MSSP is highly desirable.

  • Experience working in remote or distributed teams with strong time management, structured communication and self-directed work habits.

  • High level of integrity, discretion and professionalism when handling sensitive customer information.

  • Bachelor’s degree in Computer Science, Information Security or a related field, or equivalent practical experience.


ADDITIONAL SKILLS & CERTIFICATIONS:

  • Experience with Azure, Entra ID and Microsoft 365 security will be highly regarded.

  • Exposure to AWS, Microsoft Azure or Google Cloud security testing will be advantageous.

  • Additional experience in API, mobile application or wireless penetration testing will be an advantage.

  • Experience with SIEM and detection platforms such as Microsoft Sentinel, FortiSIEM, Splunk, QRadar or Elastic will be advantageous.

  • SOC or incident response experience will be an advantage.

  • Application security experience, including secure SDLC, SAST, DAST, source code review and API security testing, will be advantageous.

  • Scripting and automation skills using Python, PowerShell, Bash or similar languages will be highly regarded.

  • Reverse engineering and malware analysis experience will be advantageous.

  • Endpoint, EDR or XDR exposure will be an advantage.

  • OT or critical infrastructure security exposure will be advantageous.

  • Must hold at least one recognised practical penetration testing certification.

  • Preferred certifications include OSCP or CREST CRT/CCT.

  • Other relevant certifications such as OSEP, OSWE, PNPT, CPTS, CRTO, GPEN or GWAPT may be considered where supported by strong practical experience.


SOFT SKILLS:

  • Curious, methodical and technically hands-on approach, with the ability to think like an attacker while acting responsibly and professionally.

  • Senior, self-directed and delivery-focused mindset.

  • Strong judgement and ability to lead engagements independently.

  • Collaborative approach with a genuine commitment to mentoring, coaching and knowledge sharing.

  • Strong attention to detail, particularly when documenting evidence, testing steps, impact and remediation guidance.

  • Customer-focused approach with the ability to explain technical risks in clear and practical language.

  • Strong written and verbal communication skills.

  • Ability to work effectively across offensive security, SOC, SIEM, cloud, network and consulting teams.

  • Comfortable working remotely as part of an Australian-led delivery model.

  • Ability to maintain structured communication, effective handovers and alignment with Australian business expectations.

  • Commitment to continuous learning and staying current with emerging threats, tools, exploit techniques and defensive controls.


BENEFITS:

  • Remote working opportunity from Sri Lanka.

  • Opportunity to work with an Australian MSSP and Australian customers.

  • Exposure to complex international penetration testing and offensive security engagements.

  • Opportunity to work across internal network, Active Directory, external network and web application security.

  • Direct exposure to senior-level cybersecurity projects and customer environments.

  • Opportunity to mentor and collaborate with Australian cyber security professionals.

  • Professional development and continuous technical learning opportunities.

  • Exposure to broader security functions including SOC, SIEM, cloud security, vulnerability management and security consulting.


TERMS & CONDITIONS:

  • Employment Type: Full-time.

  • Location: Remote from Sri Lanka.

  • Recruitment Type: Local Recruitment.

  • Role Type: Offshore Cyber Security.

  • Primary Market: Australian customers.

  • Experience: Ideally 5+ years of hands-on penetration testing or offensive security experience.

  • Senior or lead penetration testing experience preferred.

  • Must hold at least one recognised practical penetration testing certification.

  • Other terms and conditions apply as per company policy.


HOW TO APPLY:

If you are interested and meet the above requirements, please forward your detailed CV to:

Email your CV to:

This email address is being protected from spambots. You need JavaScript enabled to view it.

Call / WhatsApp:

0777 833 575 | 0777 833 576

Office:

0117 387 882 | 0117 387 883

Our Working Hours:

Monday to Friday: 9:30 AM – 5:30 PM


Manpower Lanka Solutions (Pvt) Ltd.

12A, Ridgeway Place, Bambalapitiya, Colombo 04, Sri Lanka.


 

Our Clients