29 Aug
|
Crypto Mize
|
India
Penetration Tester jobs in Delhi at CryptoMize are open on a rolling, always-hiring basis — client demand for web, Android, and network pentesting runs continuously across our security practice, and we staff ahead of it. This is a full-time, permanent position with immediate joining, based at our New Delhi HQ, executing authorized offensive-security engagements for clients who need to know what a determined adversary would actually reach. Below is the complete posting: the responsibilities, the requirements, the seniority ladder, and the selection process. Testers whose findings developers thank them for should read to the end.
LOCATION New Delhi (HQ)
EMPLOYMENT Full-time · Permanent
AVAILABILITY Immediate · Rolling intake
COMPENSATION Discussed at screening
TRACKS ON THIS DESK25
CRAFT SKILLS NAMED12
TOOLS & SYSTEMS6
PATH STAGES4
01 01The actual work What will you actually do as a Penetration Tester at CryptoMize? 01 Run commissioned test engagements from kickoff to close: scope confirmation, test windows, communication protocol, and the daily check-ins clients on live systems require 02 Attack web applications the way a real intruder would: map the attack surface, chain the weak points, and demonstrate impact with controlled proof — never destruction 03 Test mobile builds on real devices: storage exposure, interception points, weak certificate pinning, and the trust decisions an app makes about its own server 04 Probe internal networks from a foothold: privilege paths, trust relationships, and the route from one compromised workstation to the crown jewels 05 Write the report the client's engineers will actually work from: reproduction steps, evidence captures, severity with rationale, and fixes that name the file to change 06 Return for verified retests: confirm each fix holds, close what holds, and escalate what was patched in name only 07 Test the human protocol too — authorized phishing simulations and physical-entry checks where the engagement's rules permit ROLE RESPONSIBILITIES As a Penetration Tester at CryptoMize you will identify the target systems and the goal for each engagement, review the available information, and undertake the variety of methods available to assess whether a determined adversary could breach the client’s web applications, mobile stacks, or networks — always inside a written authorization, always inside its scope.
The penetration-test process is deliberate: reconnaissance before contact, verified exploitation over scanner noise, and evidence that reconstructs the attack path for the client’s engineers. Testers here are also known as ethical hackers, and the ethics are load-bearing. You will spend your working days attempting to breach computer systems and networks — with explicit permission, within explicit boundaries, and with the client’s defense as the only beneficiary. Every finding carries dual accountability: technical accuracy in what you demonstrated, and professional judgment in how the demonstration is evidenced, stored, and eventually destroyed. The role carries a standing teaching duty: supervising pentest interns through their first client engagements, reviewing their findings drafts, and feeding conversion decisions. Remote testing of client networks alternates with on-site assessments as engagements require — and the documentation discipline travels with you either way, because at CryptoMize the report is the product; the exploit is just how it was earned. 02 02Capability profile What skills and tools does a Penetration Tester need? astro-island,astro-slot,astro-static-slot{display:contents} Craft skills12 Tools & systems6 Offer standards4 Engagement management on live client systems — communication protocol, windows, rollback triggersAttack-surface mapping before touching anythingChained exploitation demonstrated with controlled proofMobile assessment on real devicesInternal privilege-path probing from a footholdEngineer-readable reporting — reproduction, evidence, named fixesVerified-retest disciplineAuthorized phishing and physical-entry simulation where scope permitsTool judgment — proxy suites, exploit frameworks,
custom scripts each in their right placeScope obedience (absolute — the authorization is the job)Clearance eligibility and client-trust verificationTeaching testers the craft through engagement review Burp Suite Skilled (web application testing)Nmap (reconnaissance and enumeration)Metasploit Framework (exploitation)Kali Linux toolchainWireshark (traffic analysis)Custom Python/Bash tooling for engagement-specific needs Depth of demonstrated skill in the specific role disciplineClassification and scope of the client engagement the role supportsUrgency and time-sensitivity of active project requirementsTrack record built across CryptoMize engagements Also known as: pen testing jobs · pentester vacancy · ethical hacker · security tester 03 03Seniority ladder Penetration Tester — seniority path at CryptoMize Tester progression follows engagement quality — the findings you produced, the clients who requested you back, and the juniors you leveled up. The ladder below is how the security practice is actually organized. Penetration Tester Owns full-cycle assessments on assigned engagements, with report sign-off and client-facing findings duties. 1/4 Senior Penetration Tester Leads multi-platform engagements, defines rules of engagement, reviews all findings, and mentors testers and interns. 2/4 Red Team Lead Runs the offensive-security capability — adversary simulation programs, methodology standards, and engagement staffing across the practice. 3/4 Security Practice Principal The crossover track: testers who graduate into principal-level client counsel across the five domains, defending infrastructure at strategy altitude. 4/4 04 04The engagement surface CryptoMize work a Penetration Tester touches Every role plugs into live engagements across the five Penta-P domains — these are the services your work feeds. Penetration Tester · Job Opening This seat plugs into 6 live CryptoMize services across the five Penta-P domains — the work below is where yours lands. 6 SERVICESPENTA-P Penetration Testing Vulnerability Assessment Website Security Network Security Cyber Threat Intelligence Security Training WHAT DOES PENETRATION TESTER COMPENSATION DEPEND ON? Compensation is discussed during screening — never a fixed public figure, because it varies per person and per engagement. It depends on: # OFFER CONSTRUCTION FACTOR 01 Depth of demonstrated skill in the specific role discipline 02 Classification and scope of the client engagement the role supports 03 Urgency and time-sensitivity of active project requirements 04 Track record built across CryptoMize engagements
📌 Penetration Tester (India)
🏢 Crypto Mize
📍 India