Penetration Tester

2 weeks ago


Industrial Area, India MM NOVA TECH LTD Full time

About the RoleWe are looking for an experienced Cybersecurity Specialist to thoroughly test our SaaS product built using Laravel, Next.Js, Node.Js, MySQL, and MongoDB. The role involves identifying vulnerabilities, simulating real-world attacks, and ensuring our system is protected from threats such as malware, bot attacks, and data leakage. Scope of Security TestingThe security audit will cover, but not be limited to: Application Security Testing – SAST, DAST, IAST, OWASP Top 10 vulnerability checks.API Security Testing – authentication/authorization flaws, data exposure, rate-limiting, replay attacks.Database Security Testing – SQL injection (MySQL), NoSQL injection (MongoDB), encryption, DB access control.Infrastructure & Server Security Testing – cloud configuration audit, firewall review, network security, patch management.Penetration Testing – external and internal testing, red team simulations.Malware & Bot Attack Simulation – file upload vulnerabilities, malware injection, anti-bot measures.Authentication & Authorization Testing – weak password attacks, MFA testing, session hijacking prevention.Data Leakage & Privacy Testing – PII exposure checks, GDPR/CCPA compliance, log & error masking.Denial of Service (DoS/DDoS) Testing – stress/load testing, application-layer DoS prevention.Business Logic Security Testing – abuse of workflows, race condition testing. Key Responsibilities Perform comprehensive manual & automated security testing across the SaaS platform.Provide a detailed vulnerability assessment report with risk ratings and recommended fixes.Collaborate with the development team to implement security best practices.Re-test after fixes to ensure vulnerabilities are resolved. Required Skills & Experience Proven experience in penetration testing and web application security.Strong knowledge of Laravel, Next.Js, Node.Js, MySQL, MongoDB security considerations.Hands-on experience with OWASP Top 10, SAST, DAST, and vulnerability scanning tools.Expertise in SQL injection, NoSQL injection, XSS, CSRF, RCE, SSRF, privilege escalation testing.Familiarity with malware analysis and bot attack prevention techniques.Understanding of API security, encryption, and secure data handling.Experience with cloud security (AWS, Azure, or similar) is a plus.Relevant certifications (e.G., CEH, OSCP, CISSP) preferred. Deliverables Comprehensive security audit report.Actionable recommendations for remediation.Post-fix verification testing results.Initially, the role will be remote with a 4 PM to 12 AM IST shift, and later it will transition to an onsite position at our Noida office.


  • Penetration Tester

    5 days ago


    Greater Bengaluru Area, India ACL Digital Full time

    Cybersecurity Penetration Tester will work with project teams to ensure applications meet our security policies.3+ Years of ExperienceUnderstand project deliverables and application detailsRun automated and manual security checks (not limited to tools) to uncover security weaknesses in the systemPropose mitigation steps for identified risks and...

  • Penetration Tester

    3 days ago


    Greater Bengaluru Area, India ACL Digital Full time

    Cybersecurity Penetration Tester will work with project teams to ensure applications meet our security policies. 3+ Years of Experience Understand project deliverables and application details Run automated and manual security checks (not limited to tools) to uncover security weaknesses in the system Propose mitigation steps for identified risks and threats...

  • Penetration Tester

    4 days ago


    Greater Bengaluru Area, India ACL Digital Full time

    Cybersecurity Penetration Tester will work with project teams to ensure applications meet our security policies.3+ Years of ExperienceUnderstand project deliverables and application detailsRun automated and manual security checks (not limited to tools) to uncover security weaknesses in the systemPropose mitigation steps for identified risks and...

  • Penetration Tester

    5 days ago


    Greater Bengaluru Area, IN ACL Digital Full time

    Cybersecurity Penetration Tester will work with project teams to ensure applications meet our security policies.3+ Years of ExperienceUnderstand project deliverables and application detailsRun automated and manual security checks (not limited to tools) to uncover security weaknesses in the systemPropose mitigation steps for identified risks and...


  • Greater Bengaluru Area, India Festo India Full time

    Role Description Festo is establishing a Product Security Testing team in India, and we are looking for highly motivated Product Security Engineers with experience in security testing, particularly in the domain of Embedded and IoT products. We seek enthusiastic, young, and talented Product Security Specialist who are passionate about working with industrial...


  • Greater Bengaluru Area, IN Festo India Full time

    Role DescriptionFesto is establishing a Product Security Testing team in India, and we are looking for highly motivated Product Security Engineers with experience in security testing, particularly in the domain of Embedded and IoT products.We seek enthusiastic, young, and talented Product Security Specialist who are passionate about working with industrial...