01 Oct
|
EsquivaTech
|
Bengaluru
01 Oct
EsquivaTech
Bengaluru
Company Description
EsquivaTech is a cybersecurity services and solution provider based in Bengaluru, providing technical security testing and GRC (Governance Risk and Compliance) services. Our work spans penetration testing, red teaming, AI security, cloud security, and comprehensive compliance services.
Role Description
Job Title: Cyber Security Engineer
Experience: 2-3 Years
Work Mode: Hybrid
Location: Bengaluru
Joining: Immediate Joiners Preferred
About the Role
We are seeking a highly skilled, hands-on Security Engineer to join our cybersecurity consulting practice. In this client-facing role, you will be responsible for proactively identifying, analyzing, and helping remediate security vulnerabilities across a diverse range of client environments. The ideal candidate blends a technical hacker’s mindset with a consultative approach.
Should be capable of performing deep-dive manual exploitation while effectively communicating business risks and remediation strategies to external stakeholders.
Key Responsibilities
- End-to-End Penetration Testing: Conduct comprehensive, hands-on vulnerability assessments and penetration tests across Web Applications, Mobile Applications (iOS and Android), internal/external Networks, and APIs for various clients.
- Client Advisory & Communication: Lead technical walkthroughs and debrief sessions with external clients. Translate complex technical vulnerabilities into clear business risks, while providing actionable remediation guidance for developer teams.
- Engagement Management: Adapt quickly to different client environments, tech stacks, and security maturity levels. Manage time effectively across client engagements.
- Vulnerability Analysis: Identify security flaws (SQLi, XSS, CSRF, SSRF, IDOR, etc.)
to determine real-world impact, ensuring high quality results with zero false positives.
- Consultative Reporting: Write detailed, executive-friendly, and technically rich penetration testing reports tailored to the client's specific business context and compliance requirements.
Required Skills & Experience
- Experience: 2 to 3 years of dedicated, hands-on experience in penetration testing within a service-based, consulting, or MSSP setting.
- Consulting Soft Skills: Strong verbal and written communication skills. Proven ability to handle client interactions professionally, manage expectations, and act as a trusted security advisor.
- Web Application Security: Deep understanding of OWASP Top 10, modern web frameworks, and advanced exploitation techniques.
- Network Security: Proficiency in assessing both internal and external network architectures, bypassing segmentation, and pivoting.
- Mobile Security: Hands-on experience on Android and iOS pen testing, bypassing jailbreak/root detection, and analyzing mobile app traffic.
- API Security: Strong experience in testing REST and GraphQL APIs for business logic flaws and authorization bypasses.
- Core Tools: Proficiency with offensive security toolsets such as Burp Suite Pro, Nmap, Metasploit, Nessus/Qualys, Wireshark, SQLmap, and mobile testing frameworks (Frida, Objection, MobSF).
- Approach: Must be a hands-on practitioner capable of manual exploitation; not reliant solely on automated vulnerability scanners.
Preferred Certifications (Any one or more is highly desirable)
- OSCP (Offensive Security Certified Professional)
- GWAPT (GIAC Web Application Penetration Tester)
- eJPT (eLearnSecurity Junior Penetration Tester)
- CEH (Certified Ethical Hacker)
📌 Cyber Security Engineer (Bengaluru)
🏢 EsquivaTech
📍 Bengaluru