Overview
Staff Associate Penetration Tester (Security) responsible for helping govern and deliver the company’s cybersecurity defenses through penetration testing and Red Team Operations.
What you'll do
- Develop and execute penetration testing campaigns targeting infrastructure devices.
- Document findings and recommend remediation strategies.
- Collaborate with application teams to ensure vulnerabilities are addressed effectively.
- Simulate realistic multi-phase attack chains (e.g., lateral movement, privilege escalation).
- Create custom exploits, payloads, and evasion techniques against emulated and physical assets.
- Conduct threat emulation using TTPs based on real-world APTs and adversaries.
What you'll need
- 6–9 years of experience in penetration testing, ethical hacking, and/or red team operations.
- 3+ years of experience performing application penetration testing for enterprise web and mobile apps.
- Knowledge of web/mobile architectures and technologies (SPA, MPA, APIs, OAuth 2.0, JavaScript, Java, .NET).
- Knowledge of web/mobile application security vulnerabilities (OWASP Web/API/Mobile Top 10).
- Ability to extend testing to infrastructure, network, cloud, and IoT services.
- Comfort using offensive security tools and proficiency with scripting/automation in multiple languages.
- Ability to document complex attacks for technical and non-technical audiences.
- Bachelor’s degree in computer science, information security, or a related field.
Nice to have
- Certifications such as OSCP, OSEP, GPEN, GXPN, or GRPT.
- Experience simulating APT behavior and running attack plans.
- Familiarity with threat intelligence integration.
Details
- Location: Hyderabad, India.
- Employment type: Full-Time.
Read the full description and apply on the company’s own careers page.