Posted on: 26/11/2025
MANDATORY / MUST-HAVE SKILLS :
Technical Expertise :
- 7+ years of hands-on penetration testing & offensive security experience
- Red Team Operations - Minimum 2 years (initial access, lateral movement, persistence, exfiltration)
- Cloud Penetration Testing - Minimum 2 years (AWS, Azure, GCP misconfigurations, IAM attacks, container/K8s security)
- Strong experience in infrastructure penetration testing, and manual Web, Mobile & API testing
- Deep knowledge of Active Directory, network protocols, privilege escalation, exploitation
- Expertise with C2 frameworks like Cobalt Strike, Outflank, Silver, Core Impact etc.
- Strong proficiency in scripting/programming - Python, PowerShell, Bash (for automation, custom tooling)
- Ability to perform advanced offensive security assessments simulating real attacker TTPs
- Strong understanding of MITRE ATT&CK, APT tactics & modern threat landscape
Tools & Technologies :
Hands-on with offensive tools :
- Burp Suite, BloodHound, Cobalt Strike, Outflank, Silver, Core Impact, custom tool development
- Experience developing or modifying custom scripts/tools for evasion and post-exploitation
Communication & Reporting :
- Excellent report-writing: detailed exploitation steps, risk severity, reproducible evidence & remediation guidance
- Ability to communicate findings to technical teams and executive stakeholders
- Experience in client engagement, presentations, and scoping SOWs
Education :
- Bachelor's in Computer Science / IT or equivalent experience
GOOD-TO-HAVE SKILLS :
Additional Technical Skills :
- Experience in social engineering, phishing campaigns, or physical security testing
- Application security assessments (secure coding, SAST/DAST exposure)
- Hardware or embedded device testing experience
- Ability to contribute to methodology development, red team infrastructure, or tooling improvements
Certifications (High Value) :
- OSCP, OSCE, OSEP, OSED, OSWE
- CREST CRT / CCT, GIAC GPEN / GXPN / GCPN
- Cloud security certifications: AWS Security Specialty, Azure Security Engineer, GCP Professional Cloud Security
Soft / Leadership Skills :
- Experience mentoring junior pentesters
- Ability to conduct internal team training and lead knowledge-sharing sessions
- Strong analytical mindset and ability to adapt quickly to new environments/technology
Other Preferred :
- Involvement in community contributions: writing blogs, research papers, CVEs, speaking at conferences/webinars
- Experience drafting marketing or training materials
Did you find something suspicious?
Posted By
Posted in
Quality Assurance
Functional Area
QA & Testing
Job Code
1580632
Interview Questions for you
View All