Overview

Security & Penetration Tester Jobs in Nigeria at thco financial

Title: Security & Penetration Tester

Company: thco financial

Location: Nigeria

Job Summary

We are seeking a skilled Security & Penetration Tester to identify, assess, and mitigate security vulnerabilities across applications, networks, systems, and infrastructure. The successful candidate will conduct penetration tests, vulnerability assessments, security reviews, and risk analysis to strengthen the organization’s security posture and protect against cyber threats.

The role requires strong technical expertise in ethical hacking, security testing methodologies, vulnerability management, and the ability to communicate findings clearly to technical and non-technical stakeholders.

Key Responsibilities

  • Security Testing & Vulnerability Assessment
  • Conduct penetration testing on web applications, APIs, mobile applications, networks, cloud environments, and internal systems.
  • Perform vulnerability assessments and security audits to identify weaknesses and potential attack paths.
  • Simulate real-world cyberattacks using ethical hacking techniques.
  • Validate vulnerabilities and assess their potential business impact.
  • Recommend remediation strategies and security improvements.

Threat Identification & Analysis

  • Analyze security risks, misconfigurations, and vulnerabilities across systems and applications.
  • Review security controls and identify gaps against industry best practices.
  • Perform reconnaissance, exploitation, and post-exploitation activities within approved testing environments.
  • Stay updated on emerging threats, vulnerabilities, and attack techniques.

Security Reporting & Documentation

  • Prepare detailed penetration testing reports, including:
  • Vulnerability descriptions
  • Risk ratings
  • Evidence and findings
  • Exploitation impact
  • Recommended remediation steps
  • Present security findings to engineering teams, management, and relevant stakeholders.
  • Track remediation progress and validate fixes.

Security Tools & Technologies

  • Utilize security testing tools such as:
  • Burp Suite
  • OWASP ZAP
  • Nmap
  • Metasploit
  • Nessus/OpenVAS
  • Wireshark
  • Kali Linux tools
  • Perform manual security testing beyond automated scanning.
  • Support security monitoring and incident response activities when required.

Compliance & Best Practices

  • Support compliance initiatives and security assessments aligned with standards such as:
  • OWASP Top 10
  • ISO 27001
  • NIST Cybersecurity Framework
  • PCI DSS (where applicable)
  • Assist with security policies, procedures, and risk management activities.

Required Qualifications & Experience

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • 3+ years of experience in penetration testing, ethical hacking, or cybersecurity roles.
  • Strong understanding of:
  • Network security
  • Web application security
  • API security
  • Vulnerability management
  • Exploit techniques
  • Hands-on experience conducting security assessments and penetration tests.
  • Knowledge of operating systems including Linux and Windows environments.
  • Understanding of networking concepts (TCP/IP, DNS, HTTP/S, VPNs, firewalls).

Technical Skills

  • Strong knowledge of OWASP Top 10 vulnerabilities.
  • Experience with penetration testing methodologies such as:
  • PTES
  • OSSTMM
  • MITRE ATT&CK framework
  • Familiarity with scripting/programming languages such as:
  • Python
  • Bash
  • PowerShell
  • JavaScript
  • Experience testing:
  • Web applications
  • Mobile applications
  • Cloud environments
  • APIs
  • Enterprise networks

Preferred Certifications

  • Candidates with any of the following certifications are preferred:
  • Certified Ethical Hacker (CEH)
  • Offensive Security Certified Professional (OSCP)
  • CompTIA Security+
  • GIAC Penetration Tester (GPEN)
  • Certified Penetration Testing Professional (CPENT)
  • CREST certifications

Key Competencies

  • Strong analytical and problem-solving skills.
  • Ability to think like an attacker while maintaining ethical standards.
  • Excellent documentation and reporting skills.
  • Strong attention to detail.
  • Ability to work independently and collaboratively.
  • Good communication skills with technical and business teams.
  • Strong understanding of cybersecurity risks and controls.

Key Performance Indicators (KPIs)

  • Number and quality of vulnerabilities identified.
  • Accuracy and depth of penetration testing reports.
  • Reduction in recurring security vulnerabilities.
  • Timeliness of security assessments and remediation validation.
  • Compliance with security testing standards and procedures.
Upload your CV/resume or any other relevant file. Max. file size: 800 MB.