05 Aug
|
Bug Hunters Private
|
Noida
05 Aug
Bug Hunters Private
Noida
Experience: 2–3 Years
Location: Noida Sector 125
Key Responsibilities:
- Offensive Security & Advanced Penetration Testing
- Lead and perform advanced penetration testing across:
- Web applications
- APIs (REST/GraphQL)
- Mobile applications (Android/iOS)
- Internal & external infrastructure
- Active Directory environments
- Thick and thin client applications
- Cloud environments (AWS/Azure/GCP)
- Blockchain / smart contract ecosystems
- Identify and exploit:
- OWASP Top 10 (Web & API)
- Business logic vulnerabilities
- Advanced authentication & authorization bypass
- Deserialization, SSRF, RCE, IDOR
- Privilege escalation & lateral movement in AD
- Misconfigurations in hybrid/cloud environments
- Perform Active Directory attack simulations, including Kerberoasting, ACL abuse, delegation misconfigurations, and credential attacks.
- Conduct thick client and reverse engineering assessments:
- Static & agile binary analysis
- Bypassing application protections
- Identifying hardcoded secrets and crypto flaws
- Protocol reversing and traffic manipulation
- Develop custom proof-of-concept exploits and assist in controlled exploit development to demonstrate business impact.
- Perform blockchain security assessments, including:
- Smart contract reviewCommon vulnerabilities (reentrancy, overflow/underflow, access control flaws)
- Wallet and transaction security review
- Secure Code Review & DevSecOps
- Conduct manual and automated secure code reviews (SAST/DAST/SCA)
- Identify insecure coding patterns and provide remediation guidance
- Collaborate with development teams to integrate secure SDLC practices
- Support DevSecOps integration in CI/CD pipelines
- Perform architecture and design-level security reviewsSecurity Operations & Incident Response
- Lead investigation and response for complex security incidents
- Perform advanced threat hunting and log correlation
- Leverage SIEM, EDR/XDR/MDR tools for detection and response
- Conduct root cause analysis and post-incident reporting
- Develop and maintain detection use cases and security playbooks
Cloud & Infrastructure Security
- Conduct cloud security assessments (IAM, storage, network segmentation)
- Evaluate container and Kubernetes security
- Perform infrastructure hardening assessments
- Review Zero Trust architecture implementations
- Assess VPN, WAF, firewall, and segmentation controls
Team Leadership & Strategy
- Lead and mentor junior penetration testers and security engineers
- Review and validate technical reports before client/stakeholder delivery
- Manage security projects and timelines
- Define testing methodologies and quality standards
- Evaluate and recommend security tools and frameworks
- Support audits, compliance initiatives, and risk assessments
Required Skills & Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or related field
- 2–3 years of hands-on experience in offensive security and/or security operations
- Strong expertise in:
a. Web, API, and mobile penetration testing
b. .Infrastructure and Active Directory exploitation
c. Reverse engineering methodologies
- Hands-on experience with:
- a. Metasploitb. BloodHoundc. Mimikatzd. Wiresharke. SIEM platforms (Splunk/QRadar/ELK or equivalent)f. EDR/XDR/MDR toolsg. SAST/DAST/SCA tools
- Experience in report writing, executive presentations, and stakeholder communication
- Proven ability to mentor teams and manage engagements
- Mandatory certifications such as:
- CEH/eJPT
Pay: ₹700,000.00 - ₹800,000.00 per year
Work Location: In person
📌 Security Engineer (Noida)
🏢 Bug Hunters Private
📍 Noida