Penetration Testing Specialist (Bengaluru)

Penetration Testing Specialist (Bengaluru)

24 Sep
|
Audax Financial Technology (india)
|
Bengaluru

24 Sep

Audax Financial Technology (india)

Bengaluru

Summary

As a Specialist in Penetration Testing, you will plan and execute intelligence-led security testing engagements to assess Audax platform builds and strengthen the organisations security posture. Working within the Risk & Delivery function, you will design and operate offensive security tools and methodologies that emulate real-world adversary behaviour, identify exploitable weaknesses across applications, infrastructure, cloud, and mobile platforms, and translate technical findings into explicit, risk-rated guidance for Engineering and Risk stakeholders.

You will own the end-to-end planning, execution, and reporting of assigned testing engagements and contribute to the continuous improvement of penetration testing processes, tools, and their integration into the software delivery lifecycle.

Responsibilities

- Plan and execute penetration testing engagements across applications, networks, cloud environments, and mobile platforms, applying structured testing methodologies to assess the effectiveness of security controls within Audax platform builds.
- Design and develop custom scripts, tools, and attack frameworks to emulate adversary tactics, techniques, and procedures (TTPs) across the attack lifecycle, including defence-evasion techniques.
- Investigate identified vulnerabilities and threats, assess their exploitability and business impact, and produce clear, risk-rated findings with actionable remediation recommendations.
- Work with Engineering, Infrastructure, and Product stakeholders to prioritise remediation, track findings through to closure, and validate the effectiveness of implemented fixes.
- Advise stakeholders on risk exposure,



likely attack paths, and appropriate containment measures to support risk-informed decisions.
- Reverse engineer and assess iOS and Android application binaries to identify potential exploitation paths, including methods used to bypass root and jailbreak detection controls.
- Maintain and refine testing tools, playbooks, and internal frameworks based on engagement outcomes and emerging threat intelligence.
- Contribute to the continuous improvement of penetration testing processes and tools, including their integration with DevSecOps and CI/CD practices.
- Assess cloud and containerised environments, including AWS and Kubernetes, against recognised security best practices as part of the engagement scope.
- Produce clear technical and management reports summarising test results, risk exposure, and remediation guidance for relevant stakeholders.

Requirements

- 6-9 years of hands-on experience in penetration testing and vulnerability management within a global environment, including at least three years in a lead penetration testing, reverse engineering, security research, or threat analysis capacity.
- Demonstrated experience testing web applications, mobile applications, operating systems, networks,



and infrastructure using techniques such as injection testing, privilege escalation, buffer overflow exploitation, fuzzing, and vulnerability scanning.
- Strong working knowledge of the tactics, techniques, and procedures used for reconnaissance, persistence, lateral movement, defence evasion, and data exfiltration, as well as the broader threat and vulnerability landscape, including malware and emerging attack methods.
- Proficiency in one or more languages relevant to offensive security, such as Python, PowerShell, or shell scripting, along with familiarity with Objective-C, Java, Swift, or Assembly for mobile and operating-system-level security testing.
- Hands-on experience in iOS and Android reverse engineering, disassembly, decompilation, and the assessment or bypass of root and jailbreak detection controls.
- Ability to develop and demonstrate proof-of-concept exploits, including building and deploying custom modules and tailored payloads for established penetration testing frameworks.
- Solid understanding of network topologies, protocols, and enterprise infrastructure, including switches, routers, and firewalls, and their associated security implications.
- Familiarity with access control methodologies, intrusion detection systems, vulnerability and patch management tools, and endpoint security solutions.
- Experience in cloud security, particularly AWS, as well as container and Kubernetes security testing and DevSecOps/CI/CD practices.
- Ability to communicate technical risks clearly to technical and non-technical stakeholders and influence remediation decisions.

📌 Penetration Testing Specialist (Bengaluru)
🏢 Audax Financial Technology (india)
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: penetration testing specialist (bengaluru) / bengaluru