HamburgerMenu
hirist

Job Description

Work Location : Mumbai (Powai Hiranandani). It is 5 Days working and Work from Office role

Key Competencies & Skills required :

- Strong understanding of :

1. OWASP based vulnerabilities, including Web Application, API and LLM

2. Common attack chains from reconnaissance through exploitation

3. Authentication, authorization, session handling, and access control weaknesses

4. Cloud Security fundamentals, including identity, networking and security controls

- Solid knowledge of :

1. Linux and Windows systems

2. Networking fundamentals (TCP/IP, DNS, routing, firewalls, AD concepts)

3. AI System Architectures

- Experience using common security testing tools such as :

1. Burp Suite / ZAP

2. Network scanners and enumeration tools

- Ability to write or adapt scripts for testing or exploitation (e.g., Python, Bash, PowerShell)

Reporting & Communication :

- Very good written and spoken English (mandatory)

- Ability to clearly explain security findings to technical and non-technical stakeholders

Nice to have :

- At least one relevant security certification is highly preferred, such as :

1. OSCP

2. GWAPT / GPEN

3. Comparable hands-on penetration testing certifications

Minimum Educational Qualification :

- Bachelors degree in Computer Science, Information Security, or a related field (or equivalent experience)

- Candidate with non-computer science degree must have minimum 1 year of relevant experience

Certification if any :

- one or more certifications in information security CEH /OSCP /GWAPT / GPEN

Key Accountabilities & Responsibilities :

Penetration Testing Execution :

- Execute application VAPTs (web, API, mobile, desktop, infrastructure-adjacent and cloud components) using manual techniques and supporting tools

- Execute network penetration tests following standardized test cases and methodologies

- Perform cloud security assessments, including :

1. Review and testing of cloud environments

2. Identification of cloud misconfigurations, excessive permissions, insecure identities, exposed services, and weak security controls

- Perform security assessments of applications and platforms that incorporate AI, machine learning, or LLM-based components

- Perform reconnaissance, vulnerability identification, exploitation, and validation using attacker-based techniques

- Select appropriate test depth based on scope, asset criticality, and findings discovered during testing

Reporting & Documentation :

- Produce clear, structured, English-language penetration test reports, including AI-related findings where applicable, with

1. Reproducible evidence (screenshots, request/response samples, payloads, logs, scripts)

2. Accurate risk ratings aligned with CVSS and internal rating models

3. Actionable remediation guidance tailored to development, infrastructure, or AI engineering teams

- Document findings in centralized tooling (e.g., vulnerability or risk tracking systems) and support remediation tracking

Collaboration & Process Adherence :

- Work closely with :

1. IT Product Managers and application owners

2. Infrastructure, network, and platform teams

3. Security architecture and IT Security officer stakeholders

- Support test scoping activities, including identifying AI or LLM components that fall within testing scope

- Strictly follow internal penetration testing processes, reporting standards, and quality expectations

Continuous Improvement :

- Stay current with :

1. Emerging application, network, and AI-specific attack techniques

2. Using AI to increase productivity

3. Contribute to the evolution of internal testing approaches as AI-enabled systems become more common

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...