Penetration tester (India)

Penetration tester (India)

05 Sep
|
3i Infotech
|
India

05 Sep

3i Infotech

India

Job Description – Penetration Tester

Position Details

- Role: Penetration Tester
- Experience: 5–7 Years (in Penetration Testing)
- Employment Type: Full-Time
- Department: Information Security / Offensive Security

About the Role

We are seeking an experienced and highly skilled Penetration Tester to join our cybersecurity team. The ideal candidate will have deep expertise in offensive security assessments, vulnerability exploitation, application security testing, and advanced attack simulations across enterprise environments. The candidate should possess strong analytical skills, hands-on technical capabilities, and the ability to independently conduct end-to-end penetration testing engagements.

The role involves identifying security weaknesses across web applications, mobile applications, APIs, cloud infrastructure, and enterprise networks, while providing actionable remediation guidance aligned with industry best practices and regulatory requirements.

Key Responsibilities

- Execute manual penetration tests against web, mobile, API, and cloud environments to identify critical security gaps that automated tools often miss.
- Deploy and optimize advanced penetration testing tools and custom scripts to validate the exploitability of discovered vulnerabilities.
- Draft high-quality technical reports featuring detailed remediation guidance and risk-prioritized findings for both technical and executive stakeholders.
- Develop custom proof-of-concept (PoC) exploits to demonstrate the real-world impact of identified security weaknesses.
- Validate the effectiveness of security patches and configuration changes through structured and rigorous retesting procedures.
- Enhance internal offensive security frameworks and testing methodologies through continuous research and tool improvement.
- Apply deep knowledge of network protocols, operating systems, and system architectures to navigate and compromise complex enterprise environments.
- Analyse and exploit diverse vulnerability classes including XSS, SQL Injection (SQLi), SSRF, RCE, IDOR, Authentication & Authorization flaws, and complex business logic vulnerabilities.




- Perform comprehensive security assessments of REST, SOAP, and GraphQL APIs to ensure secure data exchange and access control mechanisms.
- Utilize professional offensive security toolsets including Burp Suite, Metasploit, Nessus, Nmap, Wireshark, and Kali Linux to conduct full-scope security assessments.
- Write custom automation and exploitation scripts in Python, Bash, and PowerShell to improve testing efficiency and exploit depth.
- Translate technical vulnerabilities into business-focused risk narratives through effective technical writing and communication.
- Conduct offensive operations across Linux and Windows-based infrastructures to identify environment-specific weaknesses and misconfigurations.
- Follow industry-standard penetration testing methodologies and frameworks including OWASP Testing Guide, MITRE ATT&CK;, OSSTMM, PTES, and NIST.
- Independently manage end-to-end security assessments while maintaining high standards of quality, precision, and professional accountability.
- Lead technical audits, assessment activities, and documentation efforts required for CERT-IN empanelment, regulatory audits, and compliance requirements.
- Collaborate with development, infrastructure, DevSecOps, and compliance teams to support remediation and security improvement initiatives.

Required Skills & Technical Expertise

Technical Skills

- Strong hands-on experience in Web Application, Mobile Application, API, Network, and Cloud Penetration Testing.
- Expertise in vulnerability assessment and manual exploitation techniques.
- Strong understanding of OWASP Top 10, SANS Top 25, CWE, and CVSS scoring methodologies.
- Experience with Active Directory security assessments and privilege escalation techniques.




- Knowledge of cloud security testing across AWS, Azure, and GCP environments.
- Understanding of secure authentication mechanisms including OAuth, JWT, SAML, MFA, and session management.
- Experience with source code review and secure coding concepts is preferred.
- Strong scripting and automation skills using Python, Bash, or PowerShell.
- Familiarity with CI/CD security testing and DevSecOps practices.

Tools & Platforms

- Burp Suite Professional
- Metasploit Framework
- Nessus / OpenVAS
- Nmap
- Wireshark
- Kali Linux
- OWASP ZAP
- Postman
- MobSF
- Docker & Kubernetes Security Tools
- Git and Version Control Systems

Educational Qualification

- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Information Technology, or a related field.
- Relevant industry experience may be considered in lieu of formal education.

Certifications

Mandatory Certifications (Any One)

- OSCP (Offensive Security Certified Professional)
- OSCE (Offensive Security Certified Expert)
- GPEN (GIAC Penetration Tester)
- CEH (Certified Ethical Hacker)

Preferred Certifications

- CRTO
- CRTP
- CEH
- eCPPT
- CISSP
- PNPT
- GWAPT
- CARTP

Preferred Candidate Profile

- Strong analytical and problem-solving skills.
- Excellent technical documentation and report-writing capabilities.
- Ability to work independently and manage multiple assessment projects.
- Strong communication and stakeholder management skills.
- Research-oriented mindset with continuous learning attitude.
- Experience handling enterprise-level VAPT engagements and regulatory assessments.
- Familiarity with CERT-IN audit requirements and compliance-driven security assessments.

What We Offer

- Prospect to work on advanced offensive security engagements.
- Exposure to enterprise, banking, fintech, healthcare, and cloud security projects.
- Collaborative and technically challenging work workplace.
- Continuous learning and certification support.
- Career growth in cybersecurity consulting and offensive security domains.

Location

- As per organizational requirement

📌 Penetration tester (India)
🏢 3i Infotech
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: penetration tester (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: penetration tester (india) / india