19 Sep
|
TAC Security
|
New Delhi
19 Sep
TAC Security
New Delhi
Job Description
Role Purpose
n
TAC Security is looking for a highly skilled Security Engineer – OSCP Certified with strong hands-on expertise in penetration testing, vulnerability assessment, application security, network security, and offensive security.
n
The Security Engineer will be responsible for identifying, validating, and demonstrating security vulnerabilities across web applications, APIs, mobile applications, networks, cloud environments, and infrastructure. The role requires a solid offensive-security mindset, practical exploitation skills, and the ability to provide actionable remediation guidance to clients and internal teams.
n
Key Responsibilities
n
1. Vulnerability Assessment & Penetration Testing
n
n
- Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) across applications and infrastructure.
n
- Conduct manual penetration testing rather than relying solely on automated scanning tools.
n
- Identify, validate, exploit, and document security vulnerabilities.
n
- Perform network and infrastructure penetration testing across internal and external environments.
n
- Conduct security testing of web applications, APIs, mobile applications, and cloud-based environments.
n
- Perform vulnerability verification and retesting after remediation.
n
- Evaluate vulnerabilities based on technical severity, exploitability, and potential business impact.
n
n
2. Web Application & API Security
n
n
- Perform advanced web application penetration testing aligned with OWASP Top 10 and relevant testing methodologies.
n
- Test for vulnerabilities including SQL Injection, XSS, SSRF, IDOR, authentication and authorization weaknesses, insecure deserialization, file-upload vulnerabilities, business-logic flaws, and security misconfigurations.
n
- Conduct API security assessments covering REST and other API architectures.
n
- Identify complex authorization, authentication, session-management, and business-logic vulnerabilities.
n
n
3. Network & Infrastructure Security
n
n
- Conduct external and internal network penetration testing.
n
- Perform network enumeration, service discovery, vulnerability analysis, exploitation, and privilege escalation.
n
- Assess Windows and Linux environments for security weaknesses.
n
- Conduct Active Directory security assessments and identify privilege-escalation and lateral-movement opportunities.
n
- Evaluate firewall configurations, exposed services, network segmentation, and infrastructure security controls.
n
n
4. Offensive Security & Exploitation
n
n
- Apply OSCP-level penetration-testing techniques in real-world environments.
n
- Perform manual exploitation, privilege escalation, pivoting, lateral movement, and post-exploitation activities within approved scopes.
n
- Develop or modify scripts and proof-of-concept exploits when required.
n
- Use offensive-security techniques responsibly and strictly within authorized testing environments.
n
- Maintain detailed evidence and attack paths throughout engagements.
n
n
5. Security Tools & Technologies
n
Hands-on experience with tools such as:
n
n
- Burp Suite Professional
n
- Nmap
n
- Metasploit
n
- Nessus
n
- Kali Linux
n
- Wireshark
n
- BloodHound
n
- Impacket
n
- SQLMap
n
- Nikto
n
- Gobuster/Ffuf
n
- Hydra
n
- John the Ripper/Hashcat
n
n
Candidates should understand the underlying techniques and be capable of performing manual validation rather than depending exclusively on tools.
n
6. Reporting & Remediation
n
n
- Prepare detailed and professional penetration-testing reports containing vulnerability descriptions, severity, evidence, proof of concept, business impact, and remediation recommendations.
n
- Assign severity using appropriate methodologies such as CVSS.
n
- Conduct technical walkthroughs with customers, developers, security teams, and management.
n
- Work closely with engineering teams to explain vulnerabilities and recommend practical remediation.
n
- Perform remediation validation and closure testing.
n
n
7. Research & Continuous Improvement
n
n
- Stay updated on emerging vulnerabilities, CVEs, exploitation techniques, attack methodologies, and cybersecurity threats.
n
- Research new offensive-security techniques and tools.
n
- Contribute to internal security methodologies, testing checklists, knowledge bases, automation, and security research.
n
- Participate in internal knowledge-sharing and technical training sessions.
n
n
Required Qualifications
n
n
- Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
n
- OSCP (Offensive Security Certified Professional) certification is mandatory.
n
- 3–7+ years of hands-on experience in penetration testing, VAPT, offensive security, or application security.
n
- Strong practical knowledge of:
n
- Web Application Penetration Testing
n
- API Security Testing
n
- Network Penetration Testing
n
- Active Directory Security
n
- Linux & Windows Privilege Escalation
n
- Vulnerability Assessment
n
- Exploitation & Post-Exploitation
n
- OWASP Top 10
n
- CVSS
n
- Strong understanding of TCP/IP, DNS, HTTP/HTTPS, firewalls, VPNs, proxies, authentication protocols, and network architectures.
n
- Ability to write basic automation/exploitation scripts using Python, Bash, or PowerShell.
n
- Excellent analytical, troubleshooting, documentation, and communication skills.
n
n
Preferred Qualifications
n
Additional certifications such as OSWE, OSEP, CRTP/CRTE, PNPT, GPEN, GWAPT, CEH, or eJPT would be advantageous.
n
Experience in one or more of the following would also be valuable: cloud penetration testing across AWS/Azure/GCP, mobile application security, source-code review, DevSecOps/AppSec, red teaming, threat modeling, or secure-code review.
📌 Security Engineer - OSCP (New Delhi)
🏢 TAC Security
📍 New Delhi