Overview
Penetration Tester Jobs in Philippines at CoDev
Title: Penetration Tester
Company: CoDev
Location: Philippines
- Work Arrangement: Work From Home
- Work Location: WFH Philippines
- Working Days: Mondays to Fridays if Mid or Night Shift; Available Shift Options (You may choose): PH Mid shift 5PM or PH Night shift 10 PM
We are seeking several skilled, client-facing Penetration Testers to support a high-profile, multi-year PCI DSS 4.0 compliance engagement with a major hotel chain. This is a hybrid technical and consultative role: you will leverage the Horizon3.ai NodeZero autonomous penetration testing platform to execute and automate assessments. The applicant will apply deep technical expertise to interpret findings, communicate risk in business terms, and guide client teams through prioritized remediation.
This role is open to both direct-hire candidates and qualified staff augmentation professionals. The ideal candidate is a seasoned penetration tester who is equally comfortable in a terminal and in a boardroom—technically credible, clear in communication, and genuinely personable.
Core Responsibilities
Technical Assessment & Testing
▪ Execute network, application, and infrastructure penetration tests in alignment with PCI DSS 4.0 Requirement 11.3 and related controls
▪ Operate and interpret results from the Horizon3.ai NodeZero platform
▪ Verify segmentation controls to validate CDE isolation per PCI DSS requirements
▪ Assist in documenting and explaining attack paths, exploited vulnerabilities, proof-of-concept artifacts, and evidence chains
Client Communication & Reporting
▪ Translate technical findings into executive-level risk summaries and actionable remediation roadmaps
▪ Lead findings debrief sessions with client stakeholders ranging from IT staff to C-suite executives
▪ Produce concise, well-structured summaries of penetration test reports meeting PCI DSS reporting standards
▪ Present results confidently in English; bilingual candidates may be assigned to language-matched client accounts
▪ Manage client expectations and maintain a professional, consultative relationship throughout engagements
Remediation Guidance
▪ Provide remote remediation consulting, clearly explaining what was found, how to fix it, and why it matters
▪ Prioritize findings based on exploitability, business impact, and PCI DSS compliance risk
▪ Validate remediation effectiveness through re-testing and evidence review
▪ Help client teams develop sustainable security hygiene practices beyond point-in-time testing
Compliance & Documentation
▪ Support client preparation for PCI DSS assessments, including gap analyses and evidence collection
▪ Ensure all testing outputs and documentation meet audit-ready standards and PCI DSS reporting requirements
Qualifications
▪ 2+ years of hands-on penetration testing experience (not limited to automated scanning tools)
▪ Demonstrated experience in PCI DSS environments, including CDE scoping, network segmentation, and Requirement 11 controls
▪ Proficiency with common penetration testing frameworks and toolsets such as Metasploit, Burp Suite, Nmap, Nessus/OpenVAS, BloodHound, Impacket, and similar
▪ Strong understanding of Windows and Linux environments, Active Directory attack paths, and web application vulnerabilities (OWASP Top 10)
▪ Ability to produce clear, professional penetration test reports with both executive and technical depth
▪ Strong interpersonal and client communication skills; must be comfortable working directly with clients
▪ Professional fluency in English (spoken and written)
Preferred Qualifications (Good to Have!)
▪ Experience with Horizon3.ai NodeZero or similar autonomous penetration testing platforms
▪ Prior PCI DSS engagement experience in hospitality, retail, or financial services sectors
▪ Familiarity with hotel Property Management Systems (PMS), Point-of-Sale (POS) environments, and payment processing infrastructure
▪ Bilingual or multilingual capability (Spanish, French, Mandarin, Portuguese, Arabic, or other languages are a strong advantage)
▪ Experience with cloud environments (AWS, Azure, GCP) and containerized workloads
▪ Background in social engineering, physical security testing, or red team operations
Certifications
At least one required certification must be held at the time of hire. Preferred certifications carry significant weight in candidate evaluation.
Certification | Full Name | Status
OSCP | Offensive Security Certified Professional | Preferred
CEH | Certified Ethical Hacker (EC-Council) | Accepted
GPEN | GIAC Penetration Tester | Preferred
QSA | Qualified Security Assessor (PCI SSC) | Preferred
CPTS | Certified Penetration Testing Specialist (HTB) | Preferred
eWPT / eWPTX | Web Application Penetration Tester (eLearnSecurity) | Preferred
GWAPT | GIAC Web Application Penetration Tester | Preferred
CompTIA PenTest+ | CompTIA PenTest+ | Accepted
The Ideal Candidate
Technical competence is the baseline—what sets our team apart is how we engage with clients and communicate impact.
We are looking for individuals who:
▪ Can explain complex security concepts clearly to non-technical audiences without being condescending
▪ Are proactive, organized, and capable of managing multiple client engagements simultaneously
▪ Take pride in both the technical rigor of their testing and the quality of their communication
▪ Are curious, self-directed, and continuously learning in a rapidly evolving threat landscape
▪ Demonstrate cultural awareness and sensitivity when working with diverse international clients
▪ Adapt communication style effectively depending on the audience, from C-level executives to technical engineers and compliance teams