24 Sep
|
Eleven
|
Bengaluru
Responsibilities:
· Conduct in-depth penetration testing of Web, Mobile (Android/iOS), API, and Internal, External infrastructure penetration testing
· Perform vulnerability assessments, exploitation, privilege escalation, lateral movement, and attack-path analysis.
· Conduct Active Directory, network, cloud, and application security testing.
· Execute Attack & Breach Simulation (BAS) and adversary emulation using the MITRE ATT&CK; framework.
· Plan and execute Red Team exercises simulating real-world threat actors.
· Conduct Purple Team exercises with Blue/SOC teams to validate detection and response capabilities.
· Assess and validate security controls including WAF, EDR/XDR, SIEM, IDS/IPS, IAM, and network security controls.
· Work with Blue/SOC teams to improve detection rules, logging, threat hunting, and incident-response capabilities.
· Prepare technical and executive-level reports, risk ratings, remediation recommendations, and remediation validation.
· Provide detailed security assessment reports and work with development/IT teams to implement fixes.
· Stay updated with the latest threats, vulnerabilities, CVE’s and hacking techniques.
Technical Skills Required:
· 3+ years of experience in penetration testing, ethical hacking, or offensive security.
· Robust knowledge of security testing methodologies, tools, and frameworks.
· Web: OWASP Top 10, Business Logic, Authentication & Authorization.
· API: REST, GraphQL, OAuth, JWT, BOLA/IDOR.
· Mobile: Android/iOS, Frida, MobSF, otool, Objection, Reverse Engineering, SSL Key Pinning Bypass.
· Red/Purple Teaming & MITRE ATT&CK.;
· Infrastructure: Network, Active Directory, Windows/Linux, Cloud.
· Tools: Burp Suite, Nmap, Metasploit, SQLMap, BloodHound, Impacket, Wireshark, Nessus, ffuf, Amass.
· Hands-on experience with manual and automated security testing techniques.
· Proficiency in scripting languages such as Python, Bash, or PowerShell.
· Experience with cloud security (AWS, Azure, GCP) is a plus.
· Bug Bounty / Vulnerability Research experience is a plus.
· Familiarity with secure coding practices and application security.
· Scripting: Python, PowerShell, Bash.
📌 Information Security Engineer III (Bengaluru)
🏢 Eleven
📍 Bengaluru