Penetration Testers
In 2016, the central bank of Bangladesh suffered one of the biggest bank heists in history — a criminal gang managed to steal $81 million from the country's largest bank, which was under tight security. That gang didn't storm the bank or fire a single shot like you'd see in the movies — it was an online heist. A group of internet hackers managed to break into the bank's computer systems and transfer $81 million from its accounts into other accounts belonging to them. That incident wasn't the first of its kind, nor the last — every day, thousands of financial institutions and businesses around the world face hacking attempts targeting their websites and accounts, whether for theft, ransom, or sometimes even a cyberterrorism attack meant to disrupt the operations of a country's sovereign institutions. For example, in 2022, dozens of American airports had their websites disrupted after being hit by hacker attacks. The various computer systems and networks in most companies are equipped with highly advanced security and protection software, yet despite that, hackers still manage to break in because of their exceptional ability to exploit vulnerabilities in those systems. To overcome these challenges, companies have started looking for people capable of thinking the exact same way hackers do, and who have the same techniques and tools hackers use to carry out their attacks. Companies found exactly what they needed in people called "ethical hackers" or "penetration testers" — people just like hackers, except for one key difference: they work legitimately with companies and institutions. They're hired to carry out what's called "penetration testing" — meaning they're asked to break into a company's computer systems and networks and search for the weaknesses and vulnerabilities in its security systems that hackers could exploit. Once they find those vulnerabilities, they get secured and the security software gets upgraded, and the end result is understanding how cyberattacks happen and, in turn, developing ways and means to prevent them.
Meet the Writer: Waleed Abo Omiraa
What You'll Actually Do
The core tasks and responsibilities that fill a typical day.
- Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.
- Collect stakeholder data to evaluate risk and to develop mitigation strategies.
- Conduct network and security system audits, using established criteria.
- Configure information systems to incorporate principles of least functionality and least access.
- Design security solutions to address known device vulnerabilities.
- Develop and execute tests that simulate the techniques of known cyber threat actors.
- Develop infiltration tests that exploit device vulnerabilities.
- Develop presentations on threat intelligence.
- Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.
- Discuss security solutions with information technology teams or management.
- Document penetration test findings.
- Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.
- Gather cyber intelligence to identify vulnerabilities.
- Identify new threat tactics, techniques, or procedures used by cyber threat actors.
- Identify security system weaknesses, using penetration tests.
- Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.
- Keep up with new penetration testing tools and methods.
- Maintain up-to-date knowledge of hacking trends.
- Prepare and submit reports describing the results of security fixes.
- Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.
- Update corporate policies to improve cyber security.
- Write audit reports to communicate technical and procedural findings and recommend solutions.