Penetration Tester Junior

3 days ago


Hyderabad, India NopalCyber Full time

About NopalCyber

NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Through Managed Extended Detection and Response (MXDR), Attack Surface Management (ASM), Breach and Attack Simulation (BAS), and Advisory Services, we fortify our clients' cybersecurity across both offense and defence.

Our AI-driven Nopal360° platform, NopalGo mobile app, and proprietary Cyber Intelligence Quotient (CIQ) enable organizations to quantify, track, and visualize their cybersecurity posture in real time. We democratize enterprise-grade security operations for organizations of all sizes by lowering the barrier to entry while raising the bar for security and service.

Job location
: Nopal Cyber, Hyderabad (Work from Office, 5 Days a Week)

Employment Type
: Full-time

Key Responsibilities

  • Assist in discovering and inventorying external-facing assets (domains, IPs, cloud services, APIs, etc.) as part of ongoing Attack Surface Discovery (ASD) efforts.
  • Help identify unknown, unmanaged, or misconfigured assets and support remediation to improve Attack Surface Management (ASM/EASM).
  • Operate and maintain open-source or internal tools for automated asset enumeration, monitoring, and vulnerability scanning.
  • Collect and analyse DNS records, SSL certificates, WHOIS data, and public metadata to map assets to the organization.
  • Work closely with security, infrastructure, and cloud teams to ensure visibility across on-premises, cloud, and hybrid environments.
  • Assist in evaluating and integrating ASM/EASM platforms and automation workflows.
  • Support the planning and execution of vulnerability assessments and limited penetration testing of external-facing assets, web apps, and APIs under supervision.
  • Run and interpret Dynamic Application Security Testing (DAST) scans (authenticated and unauthenticated) to identify application-layer vulnerabilities.
  • Validate, track, and assist with remediation of findings from DAST and ASD activities.
  • Stay current with emerging attack vectors and vulnerabilities relevant to attack surface management and web application security.
  • Conducting research to identify new attack vectors.

Required Skills & Experience

  • 1–3 years of experience in cybersecurity, IT, or a related technical role (security operations, vulnerability management, cloud security).
  • Basic knowledge of asset discovery tools/methods (e.g., Subfinder, Amass, Shodan, Censys, Nmap), OSINT framework and ASM/EASM concepts.
  • Understanding of TCP/IP and/or OSI Models, common Internet protocols/services (DNS, HTTP/S, SMTP, etc.) and their impact on external exposure.
  • Exposure to or hands-on experience with DAST tools (e.g., OWASP ZAP, Burp Suite, or similar) and basic VAPT methodologies for web apps and APIs.
  • Familiarity with scripting/automation using Python, Bash, or similar languages to streamline discovery or scanning tasks.
  • Ability to analyse and correlate data from multiple sources to track and verify digital assets.
  • Strong curiosity and investigative mindset with attention to detail.
  • Ability to assist in developing and presenting comprehensive attack surface discovery reports, identifying external asset exposures, and recommending prioritized remediation actions aligned with organizational security policies.
  • Good communication skills and ability to document and present findings in customers calls clearly.

Educational Qualifications

  • Bachelor's degree in engineering, Computer Science, or related discipline.
  • CEH Certification is mandatory.
  • Ability to script custom reconnaissance or scanning tools (Python, Bash, etc.).
  • Familiarity with OWASP Top 10, API security, and secure cloud architecture.
  • Participation in CTFs, security research, or responsible disclosure programs.

Personal Attributes

  • Self-starter and quick learner requiring minimal ramp-up
  • Excellent written, oral, and interpersonal communication skills
  • Highly self-motivated, self-directed, and attentive to detail
  • Ability to effectively prioritize and execute tasks in a high-pressure environment

  • Penetration Tester

    2 weeks ago


    Nanakramguda, Hyderabad, Telangana, India VATINS SYSTEMS PVT LIMITED Full time

    **Job Description for Penetration Tester** **Position**: Penetration Tester **Location**: Hyderabad, India We have an opening for a Penetration Tester to join our team and help our development initiatives. This is a great opportunity for aspiring Penetration Tester’s to obtain practical experience and make a meaningful...


  • Hyderabad, India Claranet Full time

    **About The Role**: Claranet Cyber Security is a world class business unit within Claranet, designed to give customers access to market-leading information security services spanning; training, consulting, and managed services. The penetration testing team at Claranet Cyber Security is composed of highly skilled, professional ethical hackers with a real...

  • Penetration Tester

    2 weeks ago


    Hyderabad, Telangana, India Experian Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Company DescriptionJob DescriptionJob descriptionScope of Work:Infrastructure Assessment: The Penetration Tester will analyze a variety of systems within Experian, spanning from external-facing applications to internal networks or cloud environments, ensuring all potential vectors of attack are considered. Regular Deliverables: Meeting targets is crucial....

  • Penetration Tester

    2 weeks ago


    Hyderabad, Telangana, India Experian Full time

    **Company Description** Experian unlocks the power of data to create opportunities for consumers, businesses and society. During life’s big moments - from buying a home or car, to sending a child to college, to growing a business exponentially by connecting it with new customers - we empower consumers and our clients to manage data with confidence so they...

  • Penetration Tester

    2 weeks ago


    Hyderabad, Telangana, India Castellum Labs Full time

    Job Description This position is for Network and Infrastructure Penetration Testing, NOT AppSec, NOT Web VAPT Castellum Labs is a next-generation cybersecurity technology venture based in Hyderabad, India, with global set of customer base and global ambitions. Our vision is to change the cybersecurity value model in the industry by using custom designed...

  • Penetration Tester

    2 weeks ago


    Hyderabad, India Claranet Full time

    **About The Role**: Claranet Cyber Security is a world class business unit within Claranet, designed to give customers access to market-leading information security services spanning; training, consulting, and managed services. The penetration testing team at Claranet Cyber Security is composed of highly skilled, professional ethical hackers with a real...

  • Penetration Tester

    2 weeks ago


    Hyderabad, Telangana, India ZEN Cloud Systems Private Limited Full time

    **Job Title**: Penetration Tester **Location**: Hyderabad (Work from Office) **Duration**: 6 Months Contract **Shift**: General Shift / UK Shift (5 Days Working) **Experience**: 5 - 7 Years **Notice Period**: Immediate Joiners Only **Cab Facility Available** - **Required Skills**_ - Strong knowledge of **OWASP Top 10**, vulnerability assessment, and...

  • Penetration Tester

    3 days ago


    Hyderabad, India NTT DATA Full time

    Make an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive. Your day at NTT DATAThe Penetration...


  • Hyderabad, India Claranet Full time

    **About The Role**: **Department** Sec-1 is a Claranet Group Company, established since 2001 and now providing professional standard Information Security Solutions to over 600 customers across Public and Private sectors. Sec-1 Ltd’s Continuous Security Testing (CST) team is composed of highly skilled penetration testers with a real passion for improving...


  • Hyderabad, Telangana, India [x]cube LABS Full time

    Hyderabad, Telangana, India - Permanent - IT Infrastructure - 2 - 6 years - Facebook - Twitter - LinkedIn - Whatsapp Job Title: Cloud Penetration Tester **Job Description**: - 2 - 5 Years of experience in Cloud Penetration Tester. - Strong understanding of cloud computing concepts, including IaaS, PaaS, and SaaS. - Familiarity with cloud platforms such as...