Bengaluru, Karnataka
Job Summary
To ensure on-time resolution of escalations/incidents through productive analysis as per the SLA and quality norms and ensure positive customer satisfaction.
Key Responsibilities
3.3.1 Senior Penetration Tester
Desired Outcomes: Proactively identify and exploit vulnerabilities in applications, infrastructure, and human processes through ethical hacking. Provide clear, actionable remediation guidance and contribute to a stronger security posture.
Key Responsibilities:
Conduct advanced penetration tests on web applications, mobile applications, APIs, AI/ML systems, and infrastructure.
Perform red teaming exercises to simulate real-world attacks.
Integrate security testing into DevSecOps CI/CD pipelines.
Provide expert recommendations for vulnerability remediation.
Generate comprehensive penetration test reports.
Support during ongoing security incidents
Scope/Frequency:
Tier 1 – High-Frequency Applications
Count: 9 applications
Frequency: Once every 2 months
Cycles per year per app: 6
Total annual tests: 9 × 6 = 54 penetration tests/year
These applications typically involve:
High external exposure
Sensitive data
Frequent releases or configuration changes
Regulatory or business-critical functionality
Tier 2 – Annual Applications
Count: Approx.
61–65 applications (remaining portfolio)
Frequency: Minimum once per year
Total annual tests: 61–65 tests/year
These applications represent:
Lower change frequency
Controlled exposure
Stable functionality with periodic updates
Total Estimated Application Penetration Tests Per Year
Tier 1: 54 tests
Tier 2: 61–65 tests
Total: ~115–119 tests annually
Tier 3 – Red team engagements
Count: 2 Red team engagements per year (Objective: Simulate realistic adversary behavior to assess the Security vulnerabilities)
Mandatory Capabilities:
10+ years of experience in penetration testing.
Deep expertise in OWASP Top 10, SANS Top 25, and MITRE ATT&CK; framework.
Proven experience in web, mobile, API, and infrastructure penetration testing.
Strong reporting and communication skills.
Red teaming experience
Preferred Capabilities:
OSCP, OSWE, OSCE, or equivalent certifications highly preferred.
Experience with AI/ML security testing.
Experience with cloud security testing (AWS, Azure, GCP).