Skip to content

Open nowPosted 157 days ago

Penetration Tester

djamo3 open roles

Where
Abidjan, Côte d'Ivoire
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPenetration Testerdjamo · Abidjan, Côte d'Ivoire
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on djamo's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 157 days ago

The posting

Location: Abidjan, Côte I'voire or Dakar, Senegal

About Djamo

Djamo is a Series B neobank serving over 1 million customers across Francophone Africa. We're the first fintech to receive a BCEAO microfinance license and the leading card issuer in Côte d'Ivoire. Our engineering team is 27 strong, organized into cross-functional squads that own end-to-end product experiences, from virtual cards and transactions to savings, credit, and customer support.

We're growing fast, but we're deliberate about how. We care about reliability, security, and shipping things that actually work for our customers.

Why this role exists

We're a bank. Security isn't optional, it's existential. Today we rely on external vendors for penetration testing across four scopes: our Dakar office, Abidjan office, cloud infrastructure, and applications.

We need an in-house penetration tester who knows Djamo deeply, can test continuously rather than annually, and becomes a true security partner to our engineering teams. This hire saves money from year one while dramatically improving our security posture.

What you'll do

  • Plan and execute penetration tests across all four scopes: office networks (Dakar, Abidjan), cloud infrastructure (AWS), and applications (web + mobile).
  • Conduct regular vulnerability assessments and produce clear, actionable reports for engineering teams.
  • Work with engineering squads to verify fixes and retest after remediation.
  • Contribute to Djamo's security posture by identifying systemic weaknesses, not just individual vulnerabilities.
  • Support PCI DSS compliance by providing evidence of regular security testing.
  • Stay current on emerging threats and attack techniques relevant to fintech and banking.
  • Travel periodically to Abidjan and Dakar offices for on-site network and physical security assessments.

What we're looking for

Must have:

  • 3+ years of hands-on penetration testing experience.
  • Strong web application and API security testing skills (OWASP Top 10 and beyond).
  • Network penetration testing experience (internal and external).
  • Experience with common pen testing tools: Burp Suite, Nmap, Metasploit, Nessus/OpenVAS, etc.
  • Ability to write clear, prioritized vulnerability reports that engineering teams can act on.
  • Clear communication in English: written and verbal.
  • Willingness to travel periodically between Dakar and Abidjan.

Strong plus:

  • OSCP, OSCE, OSWE, or equivalent certification.
  • CEH, GPEN, or other recognized security certifications.
  • Mobile application security testing (Android/iOS).
  • Cloud security assessment experience (AWS).
  • Experience in fintech, banking, or PCI DSS-regulated environments.
  • French-speaking.
  • Experience with infrastructure-as-code security review (Terraform, Kubernetes).

What we're NOT looking for:

  • Someone who runs automated scanners and calls it a pen test. We need manual testing depth.
  • A researcher who can find vulnerabilities but can't communicate them clearly to developers.

What success looks like after 6 months

  • You've completed a full cycle of pen tests across all four scopes.
  • Engineering teams trust your reports and act on them promptly.
  • We've reduced or eliminated our dependency on external pen test vendors.
  • You've identified and helped remediate systemic security issues, not just surface-level findings.
  • You have a testing calendar that ensures continuous coverage rather than annual point-in-time assessments.

How we work

  • Remote-first, asynchronous by default.
  • Small engineering team (27 engineers) your impact will be visible and immediate.
  • We take reliability and security seriously: we're a bank, not a social app.
  • You'll work closely with the ISSM, engineering squads, and infrastructure team.

Why work at Djamo

  • Balance between autonomy and collaboration, insight and intuition, work and life.
  • Work in small, open, friendly teams to create beloved products and services.
  • Ethical and stimulating environment.
  • Contribute to the rapid expansion of a startup in French-speaking Africa.
  • Positively impact millions by providing simple and fair banking.
  • Collaborative, fun environment with strong team spirit and a culture of continuous employee development.

We will consider all applications on the same basis. Djamo is an equal-opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. You are not ticking every box or thinking you've got that unique set of skills we haven't realized we need. Apply anyway; we're always looking to add great people at every level.

Type of contract

CDD / CDI - for residents of Côte d'Ivoire or Sénégal

Desired start date

June 2026

Sector of activity

Mobile Financial Services

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against djamo's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on djamo's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    djamo's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.