The role includes the full penetration-testing lifecycle: planning and scoping engagements, performing hands-on testing, identifying and validating attack paths, evaluating security controls, documenting findings, communicating risk, supporting remediation, and validating corrective actions. Preferred certifications include OSCP, OSEP, PNPT, GPEN, GXPN, GWAPT, GCIH, GCFA, GICSP, CISSP, CPTS, or another comparable GIAC, OffSec, Hack The Box, or recognized offensive security certification.