04 Aug
|
Bug Hunters Private
|
Noida
04 Aug
Bug Hunters Private
Noida
Experience: 1-2 Years
Location: Noida Sector 125
Key Responsibilities:
- Perform end-to-end penetration testing (black-box, gray-box, white-box) on:
- Web applications
- REST/GraphQL APIs
- Mobile applications (Android/iOS)
- Internal and external infrastructure
- Active Directory environments
- Thick client and thin client applications
- Identify and exploit vulnerabilities such as:
- OWASP Top 10 (Web & API)
- Authentication & authorization bypass
- Business logic flaws
- SSRF, deserialization, IDOR, RCE
- Infrastructure misconfigurations
- Privilege escalation & lateral movement in AD
- Conduct Active Directory security assessments, including:
a. OWASP Top 10 (Web & API) b. Authentication & authorization bypass c. Business logic flaws d. SSRF, deserialization, IDOR e. Infrastructure misconfigurations
- Perform infrastructure penetration testing:
a. Network enumeration and exploitation b. Firewall/WAF bypass techniques c. VPN security assessment d. Cloud misconfiguration testing (if applicable)
- Conduct mobile application security testing:
a. Static and dynamic analysis b. SSL pinning bypass c. Insecure storage testing d. Runtime manipulation
- Perform thick client security testing:
a. Binary analysis b. Traffic interception c. Local privilege testing d. Insecure deserialization and logic abuse
- Conduct basic reverse engineering:
a. Analyze binaries using tools like IDA/Ghidra b. Identify hardcoded secrets, insecure crypto, and logic flaws c. Modify application behavior for security validation
- Develop proof-of-concept exploits to demonstrate impact
- Prepare detailed technical reports including risk ratings (CVSS), exploitation steps, and remediation guidance
- Conduct re-testing to validate remediation fixes
- Collaborate with developers, infrastructure, and DevOps teams to remediate vulnerabilities
- Stay current with emerging exploit techniques, attack frameworks, and offensive security research
Required Skills & Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or related field
- 1–2 years of hands-on experience in penetration testing or offensive security
- Strong understanding of:
a. TCP/IP, DNS, VPNs, Firewalls b. Authentication protocols (NTLM, Kerberos, OAuth, JWT) c. Web technologies (HTTP/HTTPS, sessions, cookies, CORS)
- Hands-on experience with tools such as:
a. Burp Suite (Professional preferred) b. Nmap c. Metasploit d. BloodHound e. Mimikatz f. Wireshark g. Postman (API testing)
h. MobSF / Frida (mobile testing)
- Familiarity with:
a. Windows & Linux privilege escalation techniques b. Active Directory attack methodologies c. Web proxying and traffic interception d. Manual vulnerability validation beyond automated scans
- Strong analytical, exploitation, and troubleshooting skills
- Ability to think like an attacker and chain vulnerabilities
- Solid technical documentation and reporting skills
- Effective communication and stakeholder presentation skills
- Mandatory certifications such as:
- CEH/eJPT
Pay: ₹500,000.00 - ₹600,000.00 per year
Work Location: In person
📌 Security Engineer (Noida)
🏢 Bug Hunters Private
📍 Noida