23 Sep
|
SysTools Software
|
Pune
23 Sep
SysTools Software
Pune
Role & responsibilities
- Red Team Operations: Plan and execute objective-based Red Team engagements simulating realistic adversary behavior.
- Active Directory Security: Perform advanced AD assessments including privilege escalation, lateral movement, Kerberos/NTLM attacks, credential abuse, ACL misconfigurations, AD CS exploitation, and attack-path analysis.
- Network Penetration Testing: Conduct internal and external network penetration testing across servers, endpoints, firewalls, VPNs, switches, and exposed services.
- Advanced VAPT: Perform penetration testing of web applications, APIs, infrastructure, and other in-scope assets using a combination of manual and automated techniques.
- Adversary Simulation: Develop or modify scripts, payloads, and tooling to test the effectiveness of security controls such as EDR, AV, WAF, IDS/IPS, and network segmentation.
- Post-Exploitation: Perform privilege escalation, credential access, pivoting, tunneling, and lateral movement within authorized environments.
- Purple Teaming:
Collaborate with SOC/Blue Team members to validate detections, review attack telemetry, and improve monitoring and response capabilities.
- Reporting & Remediation: Prepare transparent technical reports covering vulnerabilities, attack chains, business impact, evidence, risk ratings, and actionable remediation.
- Mentorship: Provide technical guidance and mentorship to junior and mid-level security team members.
Preferred candidate profile
- Certifications such as OSCP, OSEP, OSWE, OSED, OSCE3, CRTO, CRTP, PNPT, CPTS, GPEN, or equivalent.
- Experience testing AWS, Azure, or GCP environments.
- Exposure to Docker, Kubernetes, and cloud-native infrastructure security.
- Experience with vulnerability research, exploit development, bug bounty programs, published CVEs, or open-source security contributions is an advantage.
📌 Senior Offensive Security Engineer(Red Team/Penetration Tester) (Pune)
🏢 SysTools Software
📍 Pune