17 Sep
|
TAC Security
|
Delhi
17 Sep
TAC Security
Delhi
Role Purpose
TAC Security is looking for a highly skilled Security Engineer – OSCP Certified with strong hands-on expertise in penetration testing, vulnerability assessment, application security, network security, and offensive security .
The Security Engineer will be responsible for identifying, validating, and demonstrating security vulnerabilities across web applications, APIs, mobile applications, networks, cloud environments, and infrastructure. The role requires a strong offensive-security mindset, practical exploitation skills, and the ability to provide actionable remediation guidance to clients and internal teams.
Key Responsibilities
1. Vulnerability Assessment & Penetration Testing
- Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) across applications and infrastructure.
- Conduct manual penetration testing rather than relying solely on automated scanning tools.
- Identify, validate, exploit, and document security vulnerabilities.
- Perform network and infrastructure penetration testing across internal and external environments.
- Conduct security testing of web applications, APIs, mobile applications, and cloud-based environments.
- Perform vulnerability verification and retesting after remediation.
- Evaluate vulnerabilities based on technical severity, exploitability, and potential business impact.
2. Web Application & API Security
- Perform advanced web application penetration testing aligned with OWASP Top 10 and relevant testing methodologies.
- Test for vulnerabilities including SQL Injection, XSS, SSRF, IDOR, authentication and authorization weaknesses, insecure deserialization, file-upload vulnerabilities, business-logic flaws, and security misconfigurations.
- Conduct API security assessments covering REST and other API architectures.
- Identify complex authorization, authentication, session-management, and business-logic vulnerabilities.
3. Network & Infrastructure Security
- Conduct external and internal network penetration testing.
- Perform network enumeration, service discovery, vulnerability analysis, exploitation, and privilege escalation.
- Assess Windows and Linux environments for security weaknesses.
- Conduct Active Directory security assessments and identify privilege-escalation and lateral-movement opportunities.
- Evaluate firewall configurations, exposed services, network segmentation, and infrastructure security controls.
4. Offensive Security & Exploitation
- Apply OSCP-level penetration-testing techniques in real-world environments.
- Perform manual exploitation, privilege escalation, pivoting, lateral movement, and post-exploitation activities within approved scopes.
- Develop or modify scripts and proof-of-concept exploits when required.
- Use offensive-security techniques responsibly and strictly within authorized testing environments.
- Maintain detailed evidence and attack paths throughout engagements.
5. Security Tools & Technologies Hands-on experience with tools such as:
- Burp Suite Professional
- Nmap
- Metasploit
- Nessus
- Kali Linux
- Wireshark
- BloodHound
- Impacket
- SQLMap
- Nikto
- Gobuster/Ffuf
- Hydra
- John the Ripper/Hashcat
Candidates should understand the underlying techniques and be capable of performing manual validation rather than depending exclusively on tools. 6. Reporting & Remediation
- Prepare detailed and professional penetration-testing reports containing vulnerability descriptions, severity, evidence, proof of concept, business impact, and remediation recommendations.
- Assign severity using appropriate methodologies such as CVSS .
- Conduct technical walkthroughs with customers, developers, security teams, and management.
- Work closely with engineering teams to explain vulnerabilities and recommend practical remediation.
- Perform remediation validation and closure testing.
7. Research & Continuous Improvement
- Stay updated on emerging vulnerabilities, CVEs, exploitation techniques, attack methodologies, and cybersecurity threats.
- Research recent offensive-security techniques and tools.
- Contribute to internal security methodologies, testing checklists, knowledge bases, automation, and security research.
- Participate in internal knowledge-sharing and technical training sessions.
Required Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- OSCP (Offensive Security Certified Professional) certification is mandatory.
- 3–7+ years of hands-on experience in penetration testing, VAPT, offensive security, or application security.
- Strong practical knowledge of:
- Web Application Penetration Testing
- API Security Testing
- Network Penetration Testing
- Active Directory Security
- Linux & Windows Privilege Escalation
- Vulnerability Assessment
- Exploitation & Post-Exploitation
- OWASP Top 10
- CVSS
- Strong understanding of TCP/IP, DNS, HTTP/HTTPS, firewalls, VPNs, proxies, authentication protocols, and network architectures.
- Ability to write basic automation/exploitation scripts using Python, Bash, or PowerShell .
- Excellent analytical, troubleshooting, documentation, and communication skills.
Preferred Qualifications Additional certifications such as OSWE, OSEP, CRTP/CRTE, PNPT, GPEN, GWAPT, CEH, or eJPT would be advantageous.
Experience in one or more of the following would also be valuable: cloud penetration testing across AWS/Azure/GCP, mobile application security, source-code review, DevSecOps/AppSec, red teaming, threat modeling, or secure-code review.
📌 Security Engineer - OSCP (Delhi)
🏢 TAC Security
📍 Delhi