08 Sep
|
Happiest Minds Technologies
|
Bengaluru
08 Sep
Happiest Minds Technologies
Bengaluru
Contract Scope &
Responsibilities ?
Core Penetration Testing: Conduct detailed penetration testing of web applications, mobile applications, thick clients, cloud-native applications, APIs, and network environments using both automated tools and manual testing techniques. ?
AI/LLM Security Testing: Assess AI chatbots, AI agents, and Model Context Protocol (MCP)-based applications, including risks introduced by AI systems and how those risks can be tested, governed, and reduced. ? Execute hands-on AI security test scenarios covering prompt injection, jailbreaks, harmful outputs, sensitive data leakage, tool misuse, hallucination, grounding failures, and policy bypass. ? Design and run adversarial prompts to test model and guardrail robustness. ?
Reporting & Remediation: Identify, classify, and prioritize vulnerabilities based on risk and business impact, and prepare clear reports with findings, evidence, and proof-of-concept details where applicable. ? Collaboration & Delivery Support: Work with internal security, development, and project teams to understand application functionality, validate risks, communicate findings, and support remediation discussions within the agreed engagement scope. ? Stay current with emerging security threats, vulnerabilities, technologies, and testing methodologies. ?
Contribute to agreed security testing templates, reporting formats, methodologies, and process documentation where required for the engagement.
Required Contractor
Profile ? Bachelor?s degree in computer science, information security, or a related discipline. ? 4+ years of hands-on experience delivering vulnerability assessment and penetration testing engagements.
? Strong understanding of OWASP Top 10 around Web, API, LLM, Agentic Apps & MCP, SANS Top 25, OSSTMM, PTES, and NIST standards. ? 2+ years of solid understanding and hands-on of common GenAI risks, including prompt injection, sensitive data leakage, insecure output handling, excessive agency, hallucination, and model misuse. ?
Ability to write and execute structured AI security test cases. ? Hands-on experience with leading application security testing tools such as HCL AppScan and Burp Suite. ? Good conceptual understanding and practical hands-on experience with SAST, DAST, and other security testing approaches relevant to software development. ?
Strong foundation in application architecture, development practices, and the software development lifecycle. ? Strong knowledge of secure software development principles, including cryptography, authentication mechanisms, and security protocols. ? Relevant certifications such as OSCP, OSWE, or CEH are a plus. ?
Strong
English communication skills, both written and verbal.
Engagement
Expectations ? Strong communication and presentation skills, with the confidence to engage effectively with stakeholders. ? Ability to work collaboratively and effectively with cross-functional and geographically dispersed teams. ?
Availability to support agreed engagement timelines and occasional coordination across global time zones, as required. ? Self-driven working style with the ability to deliver quality outputs independently and within agreed timelines. ? Ability to clearly document testing scope, assumptions, limitations, evidence, and recommendations for internal review.
Penetration Testing
📌 TEST MODULE LEAD - Penetration Testing (Bengaluru)
🏢 Happiest Minds Technologies
📍 Bengaluru