Posted 05 August, 2026
Penetration Tester (Web, API & Cloud Security)
Haumaru Whānau
Auckland, AUK, NZ
Full Time
Reference: c26288462c78202f
Job Description
Penetration Tester (Web, API & Cloud Security) Auckland, New Zealand Full-time Senior Join Haumaru Technologies as a Penetration Tester to deliver advanced, CREST-aligned security testing across web applications, APIs, mobile platforms, and cloud environments. This role focuses on real-world attack simulation, deep technical testing, and high-impact vulnerability discovery. About This Role Haumaru Technologies Limited is seeking a skilled and motivated Penetration Tester to join our offensive security team. You will be responsible for conducting advanced penetration testing engagements across enterprise and government clients, including banking platforms, SaaS applications, APIs, and cloud infrastructures. This role goes beyond traditional testing — focusing on adaptive penetration testing, chaining vulnerabilities, and simulating real-world attacker behavior to uncover critical risks. You will work closely with security architects, developers, and clients to deliver high-quality, CREST-grade reports, actionable remediation guidance, and strategic security insights. Responsibilities Perform penetration testing on: Web applications (user portals, admin panels, trading platforms) APIs (REST, GraphQL, WebSocket – public and authenticated) Cloud environments (Azure, AWS, GCP) Identify, exploit, and validate vulnerabilities across OWASP Top 10, API Top 10, and advanced attack scenarios Conduct manual testing and exploitation, avoiding over-reliance on automated tools Perform authentication, authorization, and access control testing (including privilege escalation and IDOR scenarios) Chain vulnerabilities to simulate real-world attack paths and business logic abuse Conduct secure configuration reviews and cloud misconfiguration assessments Support threat modeling exercises and provide attacker perspectives on system design Document findings with clear technical detail, risk impact, CVSS scoring, and remediation guidance Perform re-testing and validation of remediated vulnerabilities Collaborate with clients and internal teams to explain findings and provide practical remediation support Contribute to development of testing methodologies, tools, and internal frameworks Stay up to date with emerging threats, exploits, and offensive security techniques Requirements Proven experience in penetration testing or offensive security Strong hands-on experience in web and API penetration testing Deep understanding of: OWASP Top 10 & API Security Top 10 Authentication and session management vulnerabilities Access control flaws (IDOR, privilege escalation, RBAC bypass) Proficiency with tools such as: Burp Suite (advanced usage) Mobile testing tools (MobSF, Frida, Objection) Experience with manual exploitation techniques (XSS, SSRF, deserialization, auth bypass, etc.) Understanding of cloud security fundamentals (Azure/AWS/GCP) Familiarity with CI/CD and DevSecOps environments Ability to write clear, professional penetration testing reports Strong problem-solving and analytical skills #J-18808-Ljbffr