JOB SUMMARY
Perform manual and automated penetration testing activities across web applications, APIs, internal and external networks, cloud environments, Active Directory, Microsoft Entra ID, wireless environments, and social engineering engagements. Identify, validate, and document security vulnerabilities, support remediation activities, participate in client discussions, and assist in delivering high-quality penetration testing reports.
OPERATIONAL RESPONSIBILITIES
- Execute penetration testing engagements across web applications, APIs, internal and external networks, cloud environments, wireless infrastructure, Active Directory, Microsoft Entra ID, and social engineering assessments.
- Participate in kickoff calls and technical discovery sessions to understand engagement objectives, scope, and Rules of Engagement.
- Review and communicate testing prerequisites, access requirements, test accounts, VPN access, connectivity requirements, and environmental dependencies.
- Perform manual and automated security testing to identify, validate, and document security vulnerabilities.
- Conduct vulnerability validation and proof-of-concept testing to confirm exploitability and business impact.
- Test for OWASP Top 10 vulnerabilities, authentication and authorization weaknesses, security misconfigurations, privilege escalation paths, and cloud security risks.
- Document findings with detailed technical evidence, screenshots, risk ratings, business impact, and remediation recommendations.
- Develop draft technical reports and support report quality reviews.
- Participate in findings walkthroughs, readout sessions, and remediation discussions with clients and internal stakeholders.
- Perform retesting activities to validate remediation effectiveness and verify vulnerability closure.
- Maintain testing evidence, engagement documentation, and project records throughout the assessment lifecycle.
- Research emerging vulnerabilities, attack techniques, exploit methods, and security tools to improve testing effectiveness.
- Escalate critical and high-risk findings to senior consultants and the Penetration Testing Lead.
EDUCATIONAL REQUIREMENTS, TOOLS & CERTIFICATIONS
Education: Diploma/bachelors degree in computer science, Information Technology or equivalent experience.
Experience:
- 25 years of experience in Penetration Testing or VAPT.
- Experience performing web, API, network, cloud, or Active Directory assessments.
- Experience supporting global or US-based customers preferred.
- Willingness to work USA business hours.
Tools & Technologies:
- Primary VM Tools: Tenable, Rapid7 / InsightVM
- Patch / Remediation Tools: Tanium, Automox
- Risk & GRC: TruOps, Cyberfusion
- IAM / PAM: Okta, CyberArk
- Endpoint Security: CrowdStrike, SentinelOne
- Penetration Tools: Burp Suite Qualified, OWASP ZAP, Nmap, Metasploit, BloodHound, sqlmap, Nessus
- Scripting and Automation: Python, Powershell, Bash
- Reporting: Power BI, Excel, dashboards, executive reporting, ticketing workflows
Certifications:
- CEH, eJPT, eWPT, PNPT, Security+, OSCP (preferred)
📌 Penetration Testing Engineer (Hyderabad)
🏢 Shi
📍 Hyderabad