Senior Penetration Tester (Bengaluru)

Senior Penetration Tester (Bengaluru)

30 Sep
|
Audax
|
Bengaluru

30 Sep

Audax

Bengaluru

About Audax audax means courage. To have the courage to change the banking scene, eliminating constraints caused by existing legacy infrastructure. Our mission is to empower banks and financial institutions to scale and modernise at speed, reaching new customers without breaking the bank.

We began our journey supplying services to and powering Standard Chartered’s white-label plug and play Banking-as-a-Service (BaaS) solution, Standard Chartered nexus, through our technology capabilities. At audax, we seek go-getters who are hungry for growth and can bring fresh perspectives.

Website - https://audax.io/

As a Specialist in Penetration Testing, you will plan and execute intelligence-led security testing engagements to certify Audax platform builds and strengthen the organization's security posture. Working within the Risk & Delivery function, you will design and operate offensive security tooling and methodologies that emulate real-world adversary behaviour, identify exploitable weaknesses across applications, infrastructure, and mobile platforms, and translate technical findings into clear, risk-rated guidance for engineering and risk stakeholders. You will own the planning, execution, and reporting of assigned testing engagements end-to-end, and contribute to the continuous improvement of testing processes, tooling, and integration with the software delivery lifecycle.

What You'll Do

- Plan and execute penetration testing engagements across applications, networks, cloud, and mobile platforms, applying a structured testing methodology to certify security control effectiveness for Audax platform builds.
- Design and build custom scripts, tools, and attack frameworks to emulate adversary tactics, techniques, and procedures (TTPs) across the attack lifecycle, including detection-evasion approaches.
- Investigate identified vulnerabilities and threats, assess exploitability and business impact, and produce explicit, risk-rated findings with corrective action recommendations.
- Prioritize remediation with Engineering, Infrastructure, and Product stakeholders and track findings through to closure, validating remediation effectiveness.
- Advise stakeholders on risk exposure, likely attack paths,



and containment measures to support risk-informed decisions on vulnerabilities the organization could face.
- Reverse engineer and assess iOS and Android application binaries to identify exploitation paths, including evasion of root/jailbreak detection controls.
- Maintain and refine testing tooling, playbooks, and internal frameworks based on engagement outcomes and emerging threat intelligence.
- Contribute to continuous improvement of penetration testing processes and tooling, including integration with DevSecOps and CI/CD practices.
- Assess cloud and containerised environments (including AWS and Kubernetes) against security best practice as part of engagement scope.
- Produce clear technical and management reporting summarizing test results, risk exposure, and remediation guidance for relevant stakeholders.

Who You Are

- 6–9 years of hands-on experience in penetration testing and vulnerability management in a global setting, including 3+ years as a lead penetration tester, reverse engineer, researcher, or threat analyst.
- Demonstrated experience testing web applications, mobile applications, and operating systems using techniques including injection, privilege escalation, buffer overflows, fuzzing, and scanning.
- Working knowledge of tactics, techniques, and procedures (TTPs) used for reconnaissance, persistence, lateral movement, and exfiltration, and of the broader threat and vulnerability landscape, including malware and emerging attack methods.
- Proficiency in one or more offensive-security-relevant languages, such as Python, PowerShell, or shell scripting, alongside familiarity with Objective-C, Java, Swift, or Assembly for mobile/OS-level work.
- iOS and Android reverse engineering, disassembly, decompilation, and evasion of root/jailbreak detection.




- Ability to write and demonstrate proof-of-concept work from an exploitation/attack perspective, including building and deploying custom modules and tailored payloads for established testing frameworks.
- Solid understanding of networking topologies, protocols, and enterprise infrastructure (switches, routers, firewalls) and their security implications.
- Familiarity with access control methodologies, intrusion detection, vulnerability and patch management tooling, and endpoint security solutions.
- Experience in cloud security (particularly AWS), container and Kubernetes testing, and DevSecOps/CI-CD practices.
- Ability to communicate technical risk clearly to both technical and non-technical stakeholders, including influencing remediation decisions.

Why Join Us?

- Be Part of a Bold Vision – At audax, we’re not just building software – we’re transforming how financial institutions and businesses manage risk, compliance, and growth. Join a team that’s fearless in challenging the status quo.
- Flexible, People-First Workplace – We value the importance of Family, Team, Self. In that order.
- Competitive Rewards and Startup Perks – We offer competitive salaries and meaningful benefits that look after your well-being.

Privacy Notice By submitting your application, you acknowledge that you have read and understood audax’s Privacy Policy for Employees, Freelancers, Contractors and Job Applicants (the “Policy”), and consent to the collection, use and disclosure of your personal data by audax for the purposes set out in the Policy. You may withdraw consent for such collection, use and disclosure, and make an access or correction request in respect of your personal data, in accordance with the Policy by emailing [email protected].

Disclaimer: At Audax, we use AI to support our recruitment process, including reviewing applications and identifying candidates whose skills and experience best match our opportunities. AI assists our recruiters—it does not make hiring decisions. All applications are reviewed by our recruitment team, and hiring decisions are made by people. Please ensure the information you submit is accurate and reflects your own qualifications and experience.

📌 Senior Penetration Tester (Bengaluru)
🏢 Audax
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior penetration tester (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: senior penetration tester (bengaluru) / bengaluru