Job Description
About the RolenWe're looking for an Ethical Hacker to join our Red Team, focused on simulating real-world adversary tactics, techniques, and procedures (TTPs) to test and strengthen our organization's security posture. This is a hands-on offensive security role — you'll be actively finding and exploiting weaknesses before real attackers do, not just running scans and filing tickets.
n
What You'll Don
- n
- Plan and execute red team engagements, adversary simulations, and breach-and-attack simulation exercises against production and pre-production environmentsn
- Manually identify and exploit vulnerabilities across web applications, APIs, mobile apps, internal networks, and cloud infrastructure — injection flaws, authentication/authorization bypasses, business-logic abuse, IDOR/BOLA, SSRF, and privilege escalationn
- Conduct Active Directory attacks (Kerberoasting, Pass-the-Hash, Golden Ticket, lateral movement) to demonstrate real domain-compromise scenariosn
- Design and run phishing, social engineering, and physical security assessments where in scopen
- Map findings to MITRE ATT&CK; and produce explicit, evidence-backed reports with reproducible PoCs for technical and executive audiencesn
- Collaborate with the Blue Team / SOC in purple-team exercises to validate detection coverage and close gapsn
- Build and maintain custom offensive tooling and scripts to support engagements (not just operate off-the-shelf scanners)n
- Stay current on emerging attack techniques, CVEs, and adversary TTPs relevant to our industryn
n
Must-Have Qualificationsn
- n
- Hands-on experience manually finding and exploiting vulnerabilities in real environments — not just running Burp/Nessus/Nmap and forwarding outputn
- Practical Active Directory / internal network attack experience (Kerberoasting, lateral movement, privilege escalation)n
- Solid understanding of MITRE ATT&CK; and how to map attacker behavior to itn
- Comfortable scripting in Python and/or
📌 Ethical Hacker (Mumbai)
🏢 Provue
📍 Mumbai