Overview

Penetration Tester Jobs in Philippines at CoDev

Title: Penetration Tester

Company: CoDev

Location: Philippines

  • Work Arrangement: Work From Home
  • Work Location: WFH Philippines
  • Working Days: Mondays to Fridays if Mid or Night Shift; Available Shift Options (You may choose): PH Mid shift 5PM or PH Night shift 10 PM

We are seeking several skilled, client-facing Penetration Testers to support a high-profile, multi-year PCI DSS 4.0 compliance engagement with a major hotel chain. This is a hybrid technical and consultative role: you will leverage the Horizon3.ai NodeZero autonomous penetration testing platform to execute and automate assessments. The applicant will apply deep technical expertise to interpret findings, communicate risk in business terms, and guide client teams through prioritized remediation.

This role is open to both direct-hire candidates and qualified staff augmentation professionals. The ideal candidate is a seasoned penetration tester who is equally comfortable in a terminal and in a boardroom—technically credible, clear in communication, and genuinely personable.

Core Responsibilities

Technical Assessment & Testing

▪ Execute network, application, and infrastructure penetration tests in alignment with PCI DSS 4.0 Requirement 11.3 and related controls

▪ Operate and interpret results from the Horizon3.ai NodeZero platform

▪ Verify segmentation controls to validate CDE isolation per PCI DSS requirements

▪ Assist in documenting and explaining attack paths, exploited vulnerabilities, proof-of-concept artifacts, and evidence chains

Client Communication & Reporting

▪ Translate technical findings into executive-level risk summaries and actionable remediation roadmaps

▪ Lead findings debrief sessions with client stakeholders ranging from IT staff to C-suite executives

▪ Produce concise, well-structured summaries of penetration test reports meeting PCI DSS reporting standards

▪ Present results confidently in English; bilingual candidates may be assigned to language-matched client accounts

▪ Manage client expectations and maintain a professional, consultative relationship throughout engagements

Remediation Guidance

▪ Provide remote remediation consulting, clearly explaining what was found, how to fix it, and why it matters

▪ Prioritize findings based on exploitability, business impact, and PCI DSS compliance risk

▪ Validate remediation effectiveness through re-testing and evidence review

▪ Help client teams develop sustainable security hygiene practices beyond point-in-time testing

Compliance & Documentation

▪ Support client preparation for PCI DSS assessments, including gap analyses and evidence collection

▪ Ensure all testing outputs and documentation meet audit-ready standards and PCI DSS reporting requirements

Qualifications

▪ 2+ years of hands-on penetration testing experience (not limited to automated scanning tools)

▪ Demonstrated experience in PCI DSS environments, including CDE scoping, network segmentation, and Requirement 11 controls

▪ Proficiency with common penetration testing frameworks and toolsets such as Metasploit, Burp Suite, Nmap, Nessus/OpenVAS, BloodHound, Impacket, and similar

▪ Strong understanding of Windows and Linux environments, Active Directory attack paths, and web application vulnerabilities (OWASP Top 10)

▪ Ability to produce clear, professional penetration test reports with both executive and technical depth

▪ Strong interpersonal and client communication skills; must be comfortable working directly with clients

▪ Professional fluency in English (spoken and written)

Preferred Qualifications (Good to Have!)

▪ Experience with Horizon3.ai NodeZero or similar autonomous penetration testing platforms

▪ Prior PCI DSS engagement experience in hospitality, retail, or financial services sectors

▪ Familiarity with hotel Property Management Systems (PMS), Point-of-Sale (POS) environments, and payment processing infrastructure

▪ Bilingual or multilingual capability (Spanish, French, Mandarin, Portuguese, Arabic, or other languages are a strong advantage)

▪ Experience with cloud environments (AWS, Azure, GCP) and containerized workloads

▪ Background in social engineering, physical security testing, or red team operations

Certifications

At least one required certification must be held at the time of hire. Preferred certifications carry significant weight in candidate evaluation.

Certification | Full Name | Status

OSCP | Offensive Security Certified Professional | Preferred

CEH | Certified Ethical Hacker (EC-Council) | Accepted

GPEN | GIAC Penetration Tester | Preferred

QSA | Qualified Security Assessor (PCI SSC) | Preferred

CPTS | Certified Penetration Testing Specialist (HTB) | Preferred

eWPT / eWPTX | Web Application Penetration Tester (eLearnSecurity) | Preferred

GWAPT | GIAC Web Application Penetration Tester | Preferred

CompTIA PenTest+ | CompTIA PenTest+ | Accepted

The Ideal Candidate

Technical competence is the baseline—what sets our team apart is how we engage with clients and communicate impact.

We are looking for individuals who:

▪ Can explain complex security concepts clearly to non-technical audiences without being condescending

▪ Are proactive, organized, and capable of managing multiple client engagements simultaneously

▪ Take pride in both the technical rigor of their testing and the quality of their communication

▪ Are curious, self-directed, and continuously learning in a rapidly evolving threat landscape

▪ Demonstrate cultural awareness and sensitivity when working with diverse international clients

▪ Adapt communication style effectively depending on the audience, from C-level executives to technical engineers and compliance teams

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.