25 Sep
|
Provue
|
Maharashtra
25 Sep
Provue
Maharashtra
About the Role We're looking for an Ethical Hacker to join our Red Team, focused on simulating real-world adversary tactics, techniques, and procedures (TTPs) to test and strengthen our organization's security posture. This is a hands-on offensive security role — you'll be actively finding and exploiting weaknesses before real attackers do, not just running scans and filing tickets. What You'll Do Plan and execute red team engagements, adversary simulations, and breach-and-attack simulation exercises against production and pre-production environments Manually identify and exploit vulnerabilities across web applications, APIs, mobile apps, internal networks, and cloud infrastructure — injection flaws, authentication/authorization bypasses, business-logic abuse, IDOR/BOLA, SSRF, and privilege escalation Conduct Active Directory attacks (Kerberoasting, Pass-the-Hash, Golden Ticket, lateral movement) to demonstrate real domain-compromise scenarios Design and run phishing, social engineering, and physical security assessments where in scope Map findings to MITRE ATT&CK; and produce explicit, evidence-backed reports with reproducible PoCs for technical and executive audiences Collaborate with the Blue Team / SOC in purple-team exercises to validate detection coverage and close gaps Build and maintain custom offensive tooling and scripts to support engagements (not just operate off-the-shelf scanners)
Stay current on emerging attack techniques, CVEs, and adversary TTPs relevant to our industry Must-Have Qualifications Hands-on experience manually finding and exploiting vulnerabilities in real environments — not just running Burp/Nessus/Nmap and forwarding output Practical Active Directory / internal network attack experience (Kerberoasting, lateral movement, privilege escalation) Solid understanding of MITRE ATT&CK; and how to map attacker behavior to it Comfortable scripting in Python and/or Bash to build or adapt offensive tooling Can clearly document and present findings — root cause, impact, and reproduction steps — to both engineers and leadership Preferred Qualifications A public track record: CVEs, accepted bug bounty reports (with class/severity), published write-ups, or open-source security tooling contributions Red team certifications such as CRTP, CRTA, OSCP, or equivalent hands-on (not multiple-choice) credentials Experience with C2 frameworks (Cobalt Strike, Sliver) and EDR/AV evasion techniques Cloud attack-path experience (AWS/Azure/GCP IAM misconfigurations, exposed storage, over-privileged roles) Exposure to AI/LLM security — prompt injection, jailbreak testing, or MCP/agent-tool-abuse research Experience with purple-teaming or working directly with detection/blue teams to improve coverage
📌 Ethical Hacker (Maharashtra)
🏢 Provue
📍 Maharashtra