CyberSecurity (Hyderabad)

CyberSecurity (Hyderabad)

02 Oct
|
Cloudxtreme
|
Hyderabad

02 Oct

Cloudxtreme

Hyderabad

including:
o Web Application Penetration Testing
o Mobile Application Penetration Testing
o Web Services / API Penetration Testing
o Network Penetration Testing
o Thick Client Penetration Testing

Key Responsibilities • Assist in the technical scoping of security testing activities based on client requirements and architecture reviews. • Execute manual penetration testing across multiple domains, including: o Web Application Penetration Testing o Mobile Application Penetration Testing o Web Services / API Penetration Testing o Network Penetration Testing o Thick Client Penetration Testing • Conduct focused security research when not deployed on active engagements. • Analyze and understand complex application, infrastructure, and solution architecture designs to identify security weaknesses. • Provide consultative guidance to stakeholders on vulnerabilities identified, including clear and actionable remediation recommendations, both verbally and in writing. • Prepare high-quality assessment reports with concise risk articulation and business-relevant recommendations. • Enhance and update penetration testing methodologies, processes, playbooks, and standards documentation. • Maintain technical proficiency through ongoing learning, certifications, and structured training paths. • Effectively communicate the services, capabilities, and value proposition of the penetration testing team to internal and external stakeholders. • Leverage automation and scripting, including AI-assisted and AI-integrated approaches, to improve testing efficiency and coverage. • Support vulnerability research and exploit development activities using AI-enabled techniques where appropriate. • Perform security testing for LLM-enabled applications and AI systems,



including validation of common LLM-related risks and misuse scenarios. Required Qualifications • Proven experience in manual Web Application Penetration Testing. • Proven experience in manual Mobile Application Penetration Testing. • Hands-on experience in API / Web Services Penetration Testing. • Hands-on experience in Network Penetration Testing. • Hands-on experience in Thick Client Penetration Testing. • Strong understanding of common vulnerabilities, attack techniques, and remediation approaches across application and infrastructure security. • Proficiency in analyzing complex architectures and identifying potential attack paths. • Strong written and verbal communication skills, with the ability to explain technical findings to both technical and non-technical stakeholders. • Ability to provide practical, risk-based, and actionable recommendations to clients. • Experience with security testing tools, manual validation techniques, and scripting/automation to support testing activities. Preferred Qualifications • Experience with automation and scripting for penetration testing use cases.

- Hands-on experience in Web Services / API Penetration Testing. • Hands-on experience in Network Penetration Testing. • Hands-on experience in Thick Client Penetration Testing. • Robust experience with common security testing tools such as Burp Suite,



OWASP ZAP, Metasploit, Postman, Swagger, Nmap, Qualys, SQLMap, and similar tools. • Experience using Kali Linux or other dedicated penetration testing operating system platforms. • Advanced knowledge of network penetration testing, application penetration testing, and architectural security principles. • Familiarity with software security weaknesses, common vulnerability classes, and attack techniques. • Working knowledge of at least one scripting language such as Python, Bash, or PowerShell. • Familiarity with at least one programming language and framework, enabling effective review and testing of application behavior. • Strong written and verbal communication skills, including the ability to explain complex technical issues to diverse audiences. • Demonstrated experience working with diverse stakeholders, ideally in a global, multi-national environment. • Ability to manage concurrent initiatives with effective prioritization, sound judgment, and strong time management. Preferred Qualifications The following would be advantageous: • Knowledge of or experience with: o OWASP Top 10 o OWASP API Security Top 10 o OWASP Thick Client Top 10 o OWASP LLM Top 10 o MITRE ATT&CK; Framework • Experience in cloud service testing. • Exposure to reverse engineering techniques. • Familiarity with Static Application Security Testing (SAST). • Familiarity with Dynamic Application Security Testing (DAST). • Relevant certifications such as OSCP, OSWE, OSEP, GPEN, GWAPT, GMOB, eCPPT, or equivalent. • Experience with AI-assisted testing workflows, security assessment of LLM-enabled applications, or modern offensive security automation approaches.

📌 CyberSecurity (Hyderabad)
🏢 Cloudxtreme
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cybersecurity (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: cybersecurity (hyderabad) / hyderabad