Ethical hacker

About this career

Ethical hackers perform security vulnerability assessments and penetration tests in accordance with industry-accepted methods and protocols. They analyse systems for potential vulnerabilities that may result from improper system configuration, hardware or software flaws, or operational weaknesses.

Essential skills

address problems critically analyse the context of an organisation communicate with stakeholders conduct ICT code review develop code exploits engage with stakeholders execute ICT audits execute social engineering tests execute software tests identify ICT security risks identify ICT system weaknesses implement ICT risk management manage system security monitor system performance perform ICT security testing use scripting programming

Required knowledge

attack vectors building systems monitoring technology computer forensics computer programming cyber attack counter-measures cyber security ethical hacking principles ethics ICT infrastructure ICT network security risks ICT security standards ICT system integration information security strategy legal requirements of ICT products operating systems penetration testing tool security engineering software anomalies tools for ICT test automation web application security threats

Additional skills

define security policies ICT safety implement a firewall implement ICT security policies maintain ICT server manage cloud data and storage manage IT security compliances perform project management remove computer virus or malware from a computer set up cybersecurity training programmes solve ICT system problems Aircrack (penetration testing tool) Backbox (penetration testing tool) BlackArch Cain and Abel (penetration testing tool) hybrid model ICT encryption ICT security legislation information confidentiality internet governance Internet of Things John The Ripper (penetration testing tool) Kali Linux levels of software testing Maltego Metasploit Nessus Nexpose Open source model organisational resilience Outsourcing model OWASP ZAP Parrot Security OS proxy servers Samurai Web Testing Framework service-oriented modelling WhiteHat Sentinel Wireshark

Also known as

cybersecurity specialist pentester cybersecurity tester offensive cybersecurity expert vulnerability analyst ICT security tester system security tester red team expert penetration tester network security tester