Security Engineer - OSCP (Mumbai)

Security Engineer - OSCP (Mumbai)

19 Sep
|
TAC Security
|
Mumbai

19 Sep

TAC Security

Mumbai

Role PurposeTAC Security is looking for a highly skilled

Security Engineer – OSCP Certified

with strong hands-on expertise in

penetration testing, vulnerability assessment, application security, network security, and offensive security .The Security Engineer will be responsible for identifying, validating, and demonstrating security vulnerabilities across web applications, APIs, mobile applications, networks, cloud environments, and infrastructure. The role requires a robust offensive-security mindset, practical exploitation skills, and the ability to provide actionable remediation guidance to clients and internal teams.Key Responsibilities1. Vulnerability Assessment & Penetration TestingPerform end-to-end

Vulnerability Assessment and Penetration Testing (VAPT)

across applications and infrastructure.Conduct manual penetration testing rather than relying solely on automated scanning tools.Identify, validate, exploit, and document security vulnerabilities.Perform network and infrastructure penetration testing across internal and external environments.Conduct security testing of web applications, APIs, mobile applications, and cloud-based environments.Perform vulnerability verification and retesting after remediation.Evaluate vulnerabilities based on technical severity, exploitability, and potential business impact.2. Web Application & API SecurityPerform advanced web application penetration testing aligned with

OWASP Top 10

and relevant testing methodologies.Test for vulnerabilities including SQL Injection, XSS, SSRF, IDOR, authentication and authorization weaknesses, insecure deserialization, file-upload vulnerabilities, business-logic flaws, and security misconfigurations.Conduct API security assessments covering REST and other API architectures.Identify complex authorization, authentication, session-management, and business-logic vulnerabilities.3.



Network & Infrastructure SecurityConduct external and internal network penetration testing.Perform network enumeration, service discovery, vulnerability analysis, exploitation, and privilege escalation.Assess Windows and Linux environments for security weaknesses.Conduct

Active Directory security assessments

and identify privilege-escalation and lateral-movement opportunities.Evaluate firewall configurations, exposed services, network segmentation, and infrastructure security controls.4. Offensive Security & ExploitationApply OSCP-level penetration-testing techniques in real-world environments.Perform manual exploitation, privilege escalation, pivoting, lateral movement, and post-exploitation activities within approved scopes.Develop or modify scripts and proof-of-concept exploits when required.Use offensive-security techniques responsibly and strictly within authorized testing environments.Maintain detailed evidence and attack paths throughout engagements.5. Security Tools & TechnologiesHands-on experience with tools such as:Burp Suite ProfessionalNmapMetasploitNessusKali LinuxWiresharkBloodHoundImpacketSQLMapNiktoGobuster/FfufHydraJohn the Ripper/HashcatCandidates should understand the underlying techniques and be capable of performing manual validation rather than depending exclusively on tools.6. Reporting & RemediationPrepare detailed and professional penetration-testing reports containing vulnerability descriptions, severity, evidence, proof of concept, business impact, and remediation recommendations.Assign severity using appropriate methodologies such as





CVSS .Conduct technical walkthroughs with customers, developers, security teams, and management.Work closely with engineering teams to explain vulnerabilities and recommend practical remediation.Perform remediation validation and closure testing.7. Research & Continuous ImprovementStay updated on emerging vulnerabilities, CVEs, exploitation techniques, attack methodologies, and cybersecurity threats.Research new offensive-security techniques and tools.Contribute to internal security methodologies, testing checklists, knowledge bases, automation, and security research.Participate in internal knowledge-sharing and technical training sessions.Required QualificationsBachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.OSCP (Offensive Security Certified Professional) certification is mandatory.3–7+ years of hands-on experience

in penetration testing, VAPT, offensive security, or application security.Strong practical knowledge of:Web Application Penetration TestingAPI Security TestingNetwork Penetration TestingActive Directory SecurityLinux & Windows Privilege EscalationVulnerability AssessmentExploitation & Post-ExploitationOWASP Top 10CVSSStrong understanding of TCP/IP, DNS, HTTP/HTTPS, firewalls, VPNs, proxies, authentication protocols, and network architectures.Ability to write basic automation/exploitation scripts using

Python, Bash, or PowerShell .Excellent analytical, troubleshooting, documentation, and communication skills.Preferred QualificationsAdditional certifications such as

OSWE, OSEP, CRTP/CRTE, PNPT, GPEN, GWAPT, CEH, or eJPT

would be advantageous.Experience in one or more of the following would also be valuable: cloud penetration testing across AWS/Azure/GCP, mobile application security, source-code review, DevSecOps/AppSec, red teaming, threat modeling, or secure-code review.

📌 Security Engineer - OSCP (Mumbai)
🏢 TAC Security
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security engineer - oscp (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: security engineer - oscp (mumbai) / mumbai