19 Sep
|
TAC Security
|
Mumbai
19 Sep
TAC Security
Mumbai
Role PurposeTAC Security is looking for a highly skilled
Security Engineer – OSCP Certified
with strong hands-on expertise in
penetration testing, vulnerability assessment, application security, network security, and offensive security .The Security Engineer will be responsible for identifying, validating, and demonstrating security vulnerabilities across web applications, APIs, mobile applications, networks, cloud environments, and infrastructure. The role requires a robust offensive-security mindset, practical exploitation skills, and the ability to provide actionable remediation guidance to clients and internal teams.Key Responsibilities1. Vulnerability Assessment & Penetration TestingPerform end-to-end
Vulnerability Assessment and Penetration Testing (VAPT)
across applications and infrastructure.Conduct manual penetration testing rather than relying solely on automated scanning tools.Identify, validate, exploit, and document security vulnerabilities.Perform network and infrastructure penetration testing across internal and external environments.Conduct security testing of web applications, APIs, mobile applications, and cloud-based environments.Perform vulnerability verification and retesting after remediation.Evaluate vulnerabilities based on technical severity, exploitability, and potential business impact.2. Web Application & API SecurityPerform advanced web application penetration testing aligned with
OWASP Top 10
and relevant testing methodologies.Test for vulnerabilities including SQL Injection, XSS, SSRF, IDOR, authentication and authorization weaknesses, insecure deserialization, file-upload vulnerabilities, business-logic flaws, and security misconfigurations.Conduct API security assessments covering REST and other API architectures.Identify complex authorization, authentication, session-management, and business-logic vulnerabilities.3.
Network & Infrastructure SecurityConduct external and internal network penetration testing.Perform network enumeration, service discovery, vulnerability analysis, exploitation, and privilege escalation.Assess Windows and Linux environments for security weaknesses.Conduct
Active Directory security assessments
and identify privilege-escalation and lateral-movement opportunities.Evaluate firewall configurations, exposed services, network segmentation, and infrastructure security controls.4. Offensive Security & ExploitationApply OSCP-level penetration-testing techniques in real-world environments.Perform manual exploitation, privilege escalation, pivoting, lateral movement, and post-exploitation activities within approved scopes.Develop or modify scripts and proof-of-concept exploits when required.Use offensive-security techniques responsibly and strictly within authorized testing environments.Maintain detailed evidence and attack paths throughout engagements.5. Security Tools & TechnologiesHands-on experience with tools such as:Burp Suite ProfessionalNmapMetasploitNessusKali LinuxWiresharkBloodHoundImpacketSQLMapNiktoGobuster/FfufHydraJohn the Ripper/HashcatCandidates should understand the underlying techniques and be capable of performing manual validation rather than depending exclusively on tools.6. Reporting & RemediationPrepare detailed and professional penetration-testing reports containing vulnerability descriptions, severity, evidence, proof of concept, business impact, and remediation recommendations.Assign severity using appropriate methodologies such as
CVSS .Conduct technical walkthroughs with customers, developers, security teams, and management.Work closely with engineering teams to explain vulnerabilities and recommend practical remediation.Perform remediation validation and closure testing.7. Research & Continuous ImprovementStay updated on emerging vulnerabilities, CVEs, exploitation techniques, attack methodologies, and cybersecurity threats.Research new offensive-security techniques and tools.Contribute to internal security methodologies, testing checklists, knowledge bases, automation, and security research.Participate in internal knowledge-sharing and technical training sessions.Required QualificationsBachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.OSCP (Offensive Security Certified Professional) certification is mandatory.3–7+ years of hands-on experience
in penetration testing, VAPT, offensive security, or application security.Strong practical knowledge of:Web Application Penetration TestingAPI Security TestingNetwork Penetration TestingActive Directory SecurityLinux & Windows Privilege EscalationVulnerability AssessmentExploitation & Post-ExploitationOWASP Top 10CVSSStrong understanding of TCP/IP, DNS, HTTP/HTTPS, firewalls, VPNs, proxies, authentication protocols, and network architectures.Ability to write basic automation/exploitation scripts using
Python, Bash, or PowerShell .Excellent analytical, troubleshooting, documentation, and communication skills.Preferred QualificationsAdditional certifications such as
OSWE, OSEP, CRTP/CRTE, PNPT, GPEN, GWAPT, CEH, or eJPT
would be advantageous.Experience in one or more of the following would also be valuable: cloud penetration testing across AWS/Azure/GCP, mobile application security, source-code review, DevSecOps/AppSec, red teaming, threat modeling, or secure-code review.
📌 Security Engineer - OSCP (Mumbai)
🏢 TAC Security
📍 Mumbai