Penetration Tester — Tenjah
The Project
Tenjah is an AI-powered educational platform designed to help Tunisian students prepare for the baccalaureate. It combines educational content, generative AI, and adaptive learning to provide personalized support throughout their preparation.
The platform includes an AI Teacher, AI-generated exercises, voice explanations in French, Arabic and Derja, photo-based exercise correction, and personalized learning paths.
Your Mission
Assess the security of the Tenjah platform through a structured penetration testing mission, identify vulnerabilities across the web application, APIs, authentication mechanisms, and deployment environment, and provide actionable recommendations to strengthen the platform's security.
Your Responsibilities
Web & API Security
- Conduct penetration testing on the frontend, backend, and REST APIs
- Identify vulnerabilities based on the OWASP Top 10
- Test authentication, authorization, and session management
- Verify access controls between different user roles
- Test user inputs for common vulnerabilities such as injection, XSS, and CSRF
- Identify unauthorized data access and API security issues
Data & AI Security
- Assess the protection of user and educational data
- Identify risks related to data storage and exposure
- Review the management of API keys, tokens, and secrets
- Assess security risks related to AI integrations and external APIs
Infrastructure Security
- Review Docker and deployment configurations
- Identify security misconfigurations
- Check for unnecessarily exposed services, ports, or endpoints
- Analyze software dependencies for known vulnerabilities
- Evaluate the overall security posture of the deployment environment
Security Assessment & Reporting
- Document identified vulnerabilities with clear technical evidence
- Assess severity, impact, and potential exploitation scenarios
- Prioritize vulnerabilities according to their risk
- Provide concrete remediation recommendations
- Deliver a professional penetration testing report
- Perform re-testing of vulnerabilities after remediation when applicable
Technologies
Web & API Security · REST · HTTP/HTTPS · OWASP Top 10 · Burp Suite / OWASP ZAP · Nmap · Docker · Git/GitHub · Linux · Dependency Scanning Tools
Deliverables
- Complete penetration testing report
- Vulnerability inventory
- Severity and risk classification
- Technical evidence and reproduction steps
- Remediation recommendations
- Security improvement roadmap
- Re-testing results where applicable
Profile
- Background in cybersecurity, computer science, software engineering, or equivalent
- Good understanding of web application and API security
- Knowledge of the OWASP Top 10
- Familiarity with penetration testing methodologies
- Comfortable with Linux and HTTP/HTTPS
- Experience with Burp Suite, OWASP ZAP, or similar tools
- Knowledge of Docker and Git is a plus
- Strong analytical and investigative mindset
- Ability to produce clear and professional security reports
- CTF, bug bounty, or previous penetration testing experience is a plus
Mission Structure
The mission will cover four main phases: reconnaissance and security assessment, vulnerability identification and validation, reporting and remediation recommendations, followed by re-testing and final security review.
All security testing must be performed exclusively on systems and environments explicitly authorized by Tenjah.