Full time B.E./ B.Sc (IT)/ BCA/ MCA/ M.sc (IT)/ other graduates with relevant experience.
5 - 10
Mumbai
Job Responsibilities
Job Summary: The Offensive Security Expert - Red Team/ Offensive Security/ Ethical Hacker, responsible for proactively identifying and exploiting security vulnerabilities in our software applications throughout the entire Software Development Life Cycle. Operating as a key member of the in-house Red Team, this role will focus on conducting advanced penetration testing, simulating real-world attacks, and providing actionable intelligence to strengthen our overall security posture.
Responsibilities
Advanced Penetration Testing
Perform in-depth penetration tests of applications, systems, and networks, using both manual techniques and automated tools.
Identify and exploit complex vulnerabilities, including those related to application logic, authentication, authorization, and data handling.
Develop detailed penetration test reports with clear and actionable recommendations for remediation.
Red Teaming & Breach Attack Simulation:
Plan and execute realistic attack simulations against our web, mobile, and desktop applications to identify weaknesses and bypass security controls.
Develop and utilize custom exploits, tools, and techniques to mimic the tactics, techniques, and procedures (TTPs) of advanced threat actors.
Conduct social engineering campaigns to assess employee awareness and identify potential vulnerabilities.
Excellent Problem solving, Organizational skills and attention to details.
Secure Code Review (Offensive Perspective):
Conduct code reviews from an offensive perspective, identifying potential vulnerabilities that could be exploited by attackers.
Provide developers with guidance on secure coding practices and vulnerability remediation techniques.
Develop and maintain secure coding guidelines and checklists.
Vulnerability Research & Exploit Development:
Confidential o Stay up to date on the latest security threats, vulnerabilities, and exploit techniques. o Conduct vulnerability research to identify new and emerging threats.
Develop custom exploits and tools to test and demonstrate the impact of vulnerabilities.
SDLC Integration
Collaborate with development teams to integrate security testing and red teaming activities into the SDLC. o Participate in design reviews and provide security guidance on application architecture and design. o Promote a security conscious culture within the development organization.
Vulnerability
Management (Validation & Verification): o Validate and verify the effectiveness of vulnerability remediation efforts. o Retest remediated vulnerabilities to ensure they have been properly addressed.
Security
Tooling & Automation (Offensive Tools): o Evaluate, recommend, and customize offensive security tools and technologies. o Automate red teaming and penetration testing processes to improve efficiency and coverage.
- Experience and Skills: o 5 to 10 years of experience in application security, penetration testing, red teaming, or a related field. o Demonstrable experience conducting advanced penetration tests and red team engagements. o Strong understanding of web application vulnerabilities (e.g., OWASP Top 10, SANS Top 25). o Experience with various penetration testing tools and frameworks (e.g., Metasploit, Burp Suite, Kali Linux). o Experience with exploit development and reverse engineering. o Expert proficiency in one or more programming languages (e.g., Python, Java, .NET, C++). o Robust understanding of web application architectures and technologies. o Deep understanding of network protocols and security concepts. o Understanding of authentication and authorization mechanisms. o Certifications (Preferred)- OSCP, CEH, GWAPT, OSCE, OSWE etc.
📌 Job Role : Manager/ Assistant Manager – Offensive Security Expert- Red Team (Mumbai)
🏢 MCXCCL
📍 Mumbai