Skip to main content
Join us

Penetration Tester

RemoteContractRemote friendly

Penetration Tester — Tenjah

The Project

Tenjah is an AI-powered educational platform designed to help Tunisian students prepare for the baccalaureate. It combines educational content, generative AI, and adaptive learning to provide personalized support throughout their preparation.

The platform includes an AI Teacher, AI-generated exercises, voice explanations in French, Arabic and Derja, photo-based exercise correction, and personalized learning paths.

Your Mission

Assess the security of the Tenjah platform through a structured penetration testing mission, identify vulnerabilities across the web application, APIs, authentication mechanisms, and deployment environment, and provide actionable recommendations to strengthen the platform's security.

Your Responsibilities

Web & API Security

  • Conduct penetration testing on the frontend, backend, and REST APIs
  • Identify vulnerabilities based on the OWASP Top 10
  • Test authentication, authorization, and session management
  • Verify access controls between different user roles
  • Test user inputs for common vulnerabilities such as injection, XSS, and CSRF
  • Identify unauthorized data access and API security issues

Data & AI Security

  • Assess the protection of user and educational data
  • Identify risks related to data storage and exposure
  • Review the management of API keys, tokens, and secrets
  • Assess security risks related to AI integrations and external APIs

Infrastructure Security

  • Review Docker and deployment configurations
  • Identify security misconfigurations
  • Check for unnecessarily exposed services, ports, or endpoints
  • Analyze software dependencies for known vulnerabilities
  • Evaluate the overall security posture of the deployment environment

Security Assessment & Reporting

  • Document identified vulnerabilities with clear technical evidence
  • Assess severity, impact, and potential exploitation scenarios
  • Prioritize vulnerabilities according to their risk
  • Provide concrete remediation recommendations
  • Deliver a professional penetration testing report
  • Perform re-testing of vulnerabilities after remediation when applicable

Technologies

Web & API Security · REST · HTTP/HTTPS · OWASP Top 10 · Burp Suite / OWASP ZAP · Nmap · Docker · Git/GitHub · Linux · Dependency Scanning Tools

Deliverables

  • Complete penetration testing report
  • Vulnerability inventory
  • Severity and risk classification
  • Technical evidence and reproduction steps
  • Remediation recommendations
  • Security improvement roadmap
  • Re-testing results where applicable

Profile

  • Background in cybersecurity, computer science, software engineering, or equivalent
  • Good understanding of web application and API security
  • Knowledge of the OWASP Top 10
  • Familiarity with penetration testing methodologies
  • Comfortable with Linux and HTTP/HTTPS
  • Experience with Burp Suite, OWASP ZAP, or similar tools
  • Knowledge of Docker and Git is a plus
  • Strong analytical and investigative mindset
  • Ability to produce clear and professional security reports
  • CTF, bug bounty, or previous penetration testing experience is a plus

Mission Structure

The mission will cover four main phases: reconnaissance and security assessment, vulnerability identification and validation, reporting and remediation recommendations, followed by re-testing and final security review.

All security testing must be performed exclusively on systems and environments explicitly authorized by Tenjah.

Apply for this role