09 Sep
|
engineersmind
|
Maharashtra
09 Sep
engineersmind
Maharashtra
Principal Penetration Tester – Red Team Location: Pune
Experience: 7 years
Role Type: Red Team / Offensive Security
Key Responsibilities
- Conduct end-to-end Red Team engagements including reconnaissance, initial access, privilege escalation, lateral movement, persistence, and objective-based attacks.
- Perform enterprise-level penetration testing and adversary simulation across network, application, cloud, and Active Directory environments.
- Identify and exploit weaknesses in Active Directory and Azure Active Directory/Entra ID environments.
- Assess Azure cloud infrastructure for security vulnerabilities, misconfigurations, identity and access-control weaknesses.
- Perform network security assessments, including internal/external network penetration testing.
- Conduct social engineering/phishing simulations where required as part of Red Team engagements.
- Execute Red Team exercises against large and complex enterprise infrastructures.
- Document attack paths, vulnerabilities, exploitation techniques, business impact, and remediation recommendations.
- Prepare detailed technical reports and present findings to technical and client stakeholders.
Key Requirements
- 7 years of overall experience in Cybersecurity / Offensive Security.
- Strong hands-on Red Teaming experience, preferably in enterprise environments.
- OSCP certification – Mandatory.
- Strong experience with Active Directory and Azure AD/Entra ID attacks.
- Hands-on experience with Azure Cloud Security / Cloud Penetration Testing.
- Robust understanding of Networking concepts and network penetration testing.
- Experience with lateral movement, privilege escalation, credential attacks, persistence and attack-path development.
- Experience conducting end-to-end Red Team engagements, not only vulnerability assessment/VAPT.
- Ability to work on large and complex client/enterprise infrastructures.
- Strong technical reporting and client-facing communication skills.
Good to Have
- CRTO / CRTP certification
- Experience with C2 frameworks such as Cobalt Strike, Sliver, etc.
- Experience with AD attack tools and techniques such as BloodHound, Mimikatz, PowerView, Rubeus, etc.
- Experience in social engineering / phishing simulations.
- Cloud penetration testing experience across Azure/AWS.
- Experience with adversary simulation and threat-informed Red Team operations.
📌 Principle Penetration Tester – Red Team Expert (Maharashtra)
🏢 engineersmind
📍 Maharashtra