Job Summary
We are seeking a skilled and self-directed Senior Penetration Tester with 5+ years of experience to join AVEVA's Product Security team. The ideal candidate is a technically well-rounded qualified who can independently lead and execute penetration tests from scoping through final report delivery, with minimal oversight. This role demands breadth across attack surfaces including Web, APIs, OT, Mobile, as well as the depth to uncover complex vulnerabilities in both contemporary and legacy technology stacks.
Location
Preferred: Bangalore, India with hybrid ~40% office, ~60% remote.
Available alternatives: Hyderabad, Mumbai, or fully remote.
Job Type
Regular, full time, hybrid work arrangement
Responsibilities
Use a risk-based approach to rapidly identify the highest impactissues
Articulate technical and business risk of discovered issues
Coordinate security assessments with external service providers
Contribute to development of testing methodology, playbooks, and tooling
Qualifications Experience executing penetration tests independently
Essential requirements
Ability to plan, scope and independently execute end-to-end penetration tests
Experience producing high-quality reports with reproducible evidence and proof-of-concepts
Experience working directly with product teams during test and retest phases
Ability to provide actionable remediation and mitigation guidance aligned with industry practices
Frontier knowledge in state-of-the-art penetration testing techniques relevant to the evolving threat landscape
Skills and competencies
One or more relevant certifications (e.g. CEH, OSCP, GWAPT, or HTB)
Penetration testing of Web Applications, Web APIs, and Industrial software targets
Experience testing API protocols such as REST, gRPC, GraphQL, WebSocket
Established application security community presence (e.g. blog, presentations, attributed CVEs)
Experience using penetration testing tools such as Burp Suite Pro, SQLMap, SysInternals.
📌 Senior Penetration Tester Bengaluru (India)
🏢 Aveva
📍 India