Key Responsibilities - Perform in-depth penetration testing of web applications and APIs, identifying and exploiting vulnerabilities aligned with OWASP Top 10 and OWASP API Security Top 10. - Conduct specialized security assessments for AI/LLM systems, including analysis of Agentic AI workflows and security considerations related to Model Context Protocol (MCP).- Utilize tools such as Burp Suite for web and API vulnerability discovery, exploitation, and traffic manipulation during assessments. - Develop explicit, reproducible proof-of-concept exploits for identified vulnerabilities and provide detailed, practical remediation guidance to clients. - Leverage vulnerability scanners like Tenable (Nessus) to perform network and application vulnerability assessments, interpreting results to prioritize and validate findings.- Prepare comprehensive technical reports detailing assessment methodologies, findings, CVSS ratings, and strategic recommendations for various client stakeholders. - Present assessment results to technical teams and executive audiences,
articulating complex security issues and their business impact.- Collaborate with internal teams to refine offensive security methodologies and contribute to the continuous improvement of AI security testing frameworks. Requirements - 2-4 years of hands-on experience in offensive security, specifically in penetration testing. - BE/Btech degree. - Demonstrated expertise in Web Application Penetration Testing and API Penetration Testing.- Solid understanding of common application security vulnerabilities, including OWASP Top 10 and OWASP API Security Top 10. - Practical experience with AI/LLM Security Testing, encompassing Agentic AI / AI Agent security and an understanding of MCP (Model Context Protocol). - Proficiency with industry-standard penetration testing tools, including Burp Suite and vulnerability scanners like Tenable (Nessus).- Ability to articulate technical security concepts and findings clearly in written reports and verbal presentations. - This is an onsite role based in Gurugram, requiring client-side engagement. Stay updated on our latest job openings and industry insights by following us on LinkedIn: eSec Forte® Technologies!
📌 AI Security and pentesting, Gurugram (India)
🏢 Leading
📍 India