16 Sep
|
TAC Security
|
Delhi
16 Sep
TAC Security
Delhi
Role Purpose
TAC Security is looking for a highly skilled Security Engineer – OSCP Certified with strong hands-on expertise in penetration testing, vulnerability assessment, application security, network security, and offensive security.
The Security Engineer will be responsible for identifying, validating, and demonstrating security vulnerabilities across web applications, APIs, mobile applications, networks, cloud environments, and infrastructure. The role requires a strong offensive-security mindset, practical exploitation skills, and the ability to provide actionable remediation guidance to clients and internal teams.
Key Responsibilities
1. Vulnerability Assessment & Penetration Testing
- Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) across applications and infrastructure.
- Conduct manual penetration testing rather than relying solely on automated scanning tools.
- Identify, validate, exploit, and document security vulnerabilities.
- Perform network and infrastructure penetration testing across internal and external environments.
- Conduct security testing of web applications, APIs, mobile applications, and cloud-based environments.
- Perform vulnerability verification and retesting after remediation.
- Evaluate vulnerabilities based on technical severity, exploitability, and potential business impact.
2. Web Application & API Security
- Perform advanced web application penetration testing aligned with OWASP Top 10 and relevant testing methodologies.
- Test for vulnerabilities including SQL Injection, XSS, SSRF, IDOR, authentication and authorization weaknesses, insecure deserialization, file-upload vulnerabilities, business-logic flaws, and security misconfigurations.
- Conduct API security assessments covering REST and other API architectures.
- Identify complex authorization, authentication, session-management, and business-logic vulnerabilities.
3. Network & Infrastructure Security
- Conduct external and internal network penetration testing.
- Perform network enumeration, service discovery, vulnerability analysis, exploitation, and privilege escalation.
- Assess Windows and Linux environments for security weaknesses.
- Conduct Active Directory security assessments and identify privilege-escalation and lateral-movement opportunities.
- Evaluate firewall configurations, exposed services, network segmentation, and infrastructure security controls.
4. Offensive Security & Exploitation
- Apply OSCP-level penetration-testing techniques in real-world environments.
- Perform manual exploitation, privilege escalation, pivoting, lateral movement, and post-exploitation activities within approved scopes.
- Develop or modify scripts and proof-of-concept exploits when required.
- Use offensive-security techniques responsibly and strictly within authorized testing environments.
- Maintain detailed evidence and attack paths throughout engagements.
5. Security Tools & Technologies Hands-on experience with tools such as:
- Burp Suite Professional
- Nmap
- Metasploit
- Nessus
- Kali Linux
- Wireshark
- BloodHound
- Impacket
- SQLMap
- Nikto
- Gobuster/Ffuf
- Hydra
- John the Ripper/Hashcat
Candidates should understand the underlying techniques and be capable of performing manual validation rather than depending exclusively on tools. 6. Reporting & Remediation
- Prepare detailed and professional penetration-testing reports containing vulnerability descriptions, severity, evidence, proof of concept, business impact, and remediation recommendations.
- Assign severity using appropriate methodologies such as CVSS.
- Conduct technical walkthroughs with customers, developers, security teams, and management.
- Work closely with engineering teams to explain vulnerabilities and recommend practical remediation.
- Perform remediation validation and closure testing.
7. Research & Continuous Improvement
- Stay updated on emerging vulnerabilities, CVEs, exploitation techniques, attack methodologies, and cybersecurity threats.
- Research new offensive-security techniques and tools.
- Contribute to internal security methodologies, testing checklists, knowledge bases, automation, and security research.
- Participate in internal knowledge-sharing and technical training sessions.
Required Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- OSCP (Offensive Security Certified Professional) certification is mandatory.
- 3–7+ years of hands-on experience in penetration testing, VAPT, offensive security, or application security.
- Solid practical knowledge of:
- Web Application Penetration Testing
- API Security Testing
- Network Penetration Testing
- Active Directory Security
- Linux & Windows Privilege Escalation
- Vulnerability Assessment
- Exploitation & Post-Exploitation
- OWASP Top 10
- CVSS
- Strong understanding of TCP/IP, DNS, HTTP/HTTPS, firewalls, VPNs, proxies, authentication protocols, and network architectures.
- Ability to write basic automation/exploitation scripts using Python, Bash, or PowerShell.
- Excellent analytical, troubleshooting, documentation, and communication skills.
Preferred Qualifications Additional certifications such as OSWE, OSEP, CRTP/CRTE, PNPT, GPEN, GWAPT, CEH, or eJPT would be advantageous.
Experience in one or more of the following would also be valuable: cloud penetration testing across AWS/Azure/GCP, mobile application security, source-code review, DevSecOps/AppSec, red teaming, threat modeling, or secure-code review.
📌 Security Engineer - OSCP (Delhi)
🏢 TAC Security
📍 Delhi