Codalyst Tech
Infrastructure

Hire a Dedicated Cybersecurity / Penetration Testing Engineer

A Codalyst Tech security engineer is a certified professional who works exclusively on your security posture for the duration of the engagement. Whether you need regular penetration tests, a compliance programme run through to audit readiness, or a permanent security function embedded alongside your development team, our engineers bring offensive and defensive security expertise across web applications, cloud infrastructure, APIs, and network environments. They are not consultants parachuted in for a one-time report , they operate as a member of your team, attending standups, triaging security issues in your backlog, and providing developer coaching on secure coding practices.

Full-time availablePart-time availablePart-time availableOnboards in 5 days

Monthly rate

Part-time

$1,500$2,500/mo

Full-time

$2,800$4,500/mo

Western equivalent: ~$11,000/mo

Save up to 59% vs AU/UK/US hire

Send Your Requirements

Why Codalyst Tech

Company-backed, not freelance

You hire through us: a registered company with a clear contract, NDA protection, and an escalation path if anything goes wrong.

Company-backed contract, not a freelancer agreement

Exclusive assignment, not shared across clients

Pre-vetted and interview-approved before you commit

Onboarded within 7 business days

What they do

Responsibilities

What your dedicated Cybersecurity / Penetration Testing Engineer will own as part of your team.

  • Conduct regular penetration tests on web applications, APIs, and infrastructure
  • Manage vulnerability lifecycle: discovery → triage → remediation tracking → re-test
  • Configure and maintain SIEM rules, alerting thresholds, and threat dashboards
  • Lead compliance programme delivery (SOC 2, ISO 27001, PCI DSS, GDPR)
  • Review pull requests for security anti-patterns and injection vulnerabilities
  • Write and maintain security policies, runbooks, and incident response playbooks
  • Conduct threat modelling for new features and architectural changes
  • Provide developer security training and phishing simulation programmes
  • Manage cloud security configuration (IAM, security groups, WAF, logging)
  • Coordinate with external auditors and respond to security questionnaires

Expertise

Core skills

Web application penetration testing (OWASP Top-10)Network and infrastructure security assessmentCloud security (AWS, Azure, GCP)SIEM tuning and threat detection rule writingCompliance frameworks (SOC 2 Type II, ISO 27001, PCI DSS, GDPR)Secure code review (SAST/DAST)Incident response and digital forensicsContainer and Kubernetes security hardeningIdentity and access management designThreat intelligence and threat modelling

Tooling

Tools & platforms

Burp Suite ProMetasploitNmapNessusOpenVASSplunk / Elastic SIEM / WazuhAWS Security Hub / GuardDutySnyk / Semgrep / SonarQubeVanta / DrataCrowdStrike / SentinelOneOkta / AWS IAMJira / LinearSlack / Teams

Where this role adds value

Industries we serve with this role

A dedicated Cybersecurity / Penetration Testing Engineer delivers measurable impact across 4 industries. Click any card to learn how we work within that sector.

Ready to hire a dedicated Cybersecurity / Penetration Testing Engineer?

Tell us your requirements and timezone. We will present matched candidates within 7 business days.