29 Aug
|
Cyient
|
Bengaluru
We are seeking an experienced Penetration Tester - Leader to perform offensive security testing on embedded devices (automotive or medical device or Iot) , network devices, network IT/OT infrastructure & backend/cloud applications. The role involves identifying security vulnerabilities through manual and automated penetration testing, reverse engineering in compliance with industry-specific cybersecurity standards (Automotive, Healthcare, OT, IT) and project requirements.
Key Responsibilities
- Perform Threat analysis and risk assessment
- Conduct security assessments on:
- Embedded/ IOT devices
- Cloud/Web apps
- IT/OT infrastructure
- Android & iOS apps
- Perform firmware extraction, analysis, and reverse engineering
- Identify, exploit, and document vulnerabilities with clear risk and remediation guidance
- Collaborate with development and system teams to validate fixes and retest vulnerabilities
- Prepare penetration test reports for customers and internal stakeholders
- Knowledge of secure coding flaws
Technical Skills
- Solid hands-on experience in penetration testing methodologies
- Proficiency with Kali Linux and Linux-based testing environments
- Hands-on usage of tools such as:
- Burp Suite
- Metasploit
- Nmap
- Wireshark
- Ghidra / IDA Pro
- Experience in reverse engineering of embedded firmware (ARM, PowerPC, TriCore, etc.)
- Familiarity with bootloaders, secure boot, and firmware update mechanisms
- Understanding of hardware attack surfaces and mitigation techniques
Tools & Platforms
- Kali Linux, Ubuntu, embedded Linux
- Burp Suite, Wireshark, Nmap, Metasploit
- Ghidra, IDA Pro, Binwalk
- Python / Bash scripting for automation (preferred)
Certifications (Preferred) Demonstrate strong offensive security capabilities supported by industry‑recognized certifications and verifiable achievements, including:
- Proven presence in leading Security Hall of Fame / Acknowledgment Lists from global technology vendors (e.g. Bugcrowd, HackerOne).
- Preferred certifications are
- CREST Certified Tester (CCT / CRT / CCT-INF)
- OSCP / OSWE / GWAPT
- Offensive Security or INE/eLearnSecurity certifications, such as: OSEP, ejpt, eCPPT, eWPT/eWPTX, eCPTX
- Documented contribution to the cybersecurity community through published CVEs listed under the candidate’s name. Participation in responsible disclosure programs with publicly available acknowledgements or awards.
- Demonstrated excellence through participation in national and international cybersecurity hackathons and completion of advanced CTF challenges. Achieved top‑tier rankings on offensive‑training platforms such as Hack The Box, TryHackMe, and other similar competitive environments.
- Strong portfolio of security research, exploit development, vulnerability analysis, or open-source security tool contributions.
Standards & Framework Awareness
- OWASP Testing Methodology
- Familiarity with Threat Analysis and Risk Assessment and threat-based testing
Behavioral & Professional Skills
- Strong analytical and problem-solving skills
- Ability to think like an attacker and communicate risk clearly
- Excellent technical documentation and reporting skills
- Comfortable with customer-facing discussions and technical reviews
- Ability to work independently and in cross-functional teams
📌 Security Test Engineer (Bengaluru)
🏢 Cyient
📍 Bengaluru