Penetration Tester

2 months ago


Remote, India Claranet Full time

**About The Role**:
**Role**

The primary function of the Security Analyst in the CST team is to continually review the customers’ defined scope for vulnerabilities, identify additional targets that should be included in the scope, and report these to the client in a timely, accurate, and comprehensive manner. The Security Analyst is also responsible for pre-engagement activities including scoping, statements of work, working with customers to determine their testing requirements and restrictions, and on boarding customers into the service.

**Essential duties & responsibilities**:
The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack surface for new vulnerabilities, changes in the scope of the attack surface, and proactively inform customers of discovered issues along with recommended remediation; with the overall aim of reducing the lifetime of each vulnerability. Manual testing includes identification of issues which automation alone could not identify, exploitation of all issues, often chaining multiple findings together in order to determine the true impact of vulnerabilities for the customer.
- Pre-engagement activities including scoping of assessments and statements of work, and determining customer requirements and restrictions.
- On boarding customers into the service including configuration of continual scanning, and liaising with customer to resolve issues which may reduce the effectiveness of scanning.
- Monitoring of the customers’ external perimeter for changes, and proactive discovery of new targets to include within the customer’s scope.
- Manual identification and exploitation of vulnerabilities.
- Manual verification and exploitation of scanner findings.
- Detailed analysis of issues identified and exposure for the customer including proof of concept, reproduction steps, and recommended remediation.
- Communication of findings to the customer in a detailed, accurate and manageable manner both orally and through written vulnerability/scope notifications and periodic summaries.
- Assisting in the continual development of the team and service through research and development activities. This includes the development of in-house tools the implementation of tools released to the community, and design and documentation of new and existing internal systems and processes.
- Continual professional development to maintain and develop knowledge and technical competencies.
- Maintain professional technical qualifications to demonstrate competency to our clients.
- Contributing to the writing and publishing of whitepapers and advisories.
- Undertaking projects and support tasks as appropriate to the role.

**About You**:
**Position specifications**

**Essential**:

- Excellent written and spoken English including presentation, structure, spelling, and grammar. Along with experience conveying technical information in an accessible manner.
- Core computing skills including but not limited to:

- Networking fundamentals - understanding of OSI Model, TCP/IP, HTTP, DNS, SMB, SMTP and relevant tools.
- Microsoft Windows and Office proficiency along with proficiency in one or more Linux distributions.
- REST APIs, SOAP APIs, XML and JSON formats.
- Vulnerability identification and exploitation (not limited to OWASP Top 10).
- Experience with common assessment tools such as MITM proxies (e.g. Burp Suite Pro) and SQLMap.
- Good knowledge of internal and external infrastructure technologies and security assessment including but not limited to:

- Identification and exploitation of misconfigurations or known vulnerabilities in common enterprise infrastructure and services (Windows Domains, Linux servers, virtualisation, databases, switches/routers, etc).
- Windows and Linux Sandbox/Desktop Breakout.
- Knowledge of a scripting language such as Python (preferred), Ruby, PowerShell, or Bash, for the development of new, or editing existing, tools.
- Excellent time management including setting priorities and goals to complete assigned and arising tasks.

**Desirable**:

- Knowledge of Open Source Intelligence gathering techniques. Including but not limited to use of Google dorks, DNS, domain registration, certificate transparency, and other public sources of information.
- Experience with live bug bounties, particularly where automation has been implemented.
- Knowledge of security considerations in the cloud (AWS, Azure, and GCP), particularly identifying vulnerable configurations through management and API access along with exploitation of web/infrastructure vulnerabilities specific to cloud environments.

**Desirable Certifications**:

- CRT - CREST Registered Penetration Tester (or above).
- OSCP - Offensive Security Certified Pr


  • Penetration Tester

    3 weeks ago


    Remote, India Uplers Full time

    **Penetration Tester** **Experience**: 3+ years **Expected Notice Period**: 2 to 4 Weeks **Shift**: 4:00AM to 1:00PM IST **Opportunity Type**: Remote **Placement Type**: Contractual **Contract Duration**: Full-Time, 12 Months **(*Note: This is a requirement for one of Uplers' Partners)** **What do you need for this opportunity?** **Primary...

  • Penetration Tester

    3 weeks ago


    Remote, India Simba Virtual Assistance Services Full time

    Currently we are hiring for the position of penetration tester. Good knowledge on cyber security and at least of 2 years experience in the same field. Kindly send a detailed resume for considered. **Job Types**: Full-time, Temporary **Salary**: ₹18,027.64 - ₹40,000.00 per month Schedule: - Fixed shift - Monday to Friday - Night...

  • Penetration Tester

    2 months ago


    Remote, India Agylex-Sprinx Global Full time

    **Location**:UAE (Relocation Needed) **Duration**: 12 months + 12 months **Position Overview**: **Key Responsibilities**: - Collaborate closely with interdisciplinary teams to analyze and interpret security assessment outcomes, furnishing actionable recommendations for remediation. - Remain abreast of the latest cybersecurity trends, tools, and...

  • Penetration Tester

    1 day ago


    Remote, India Agylex-Sprinx Global Full time

    **Location**:UAE (Relocation Needed) **Duration**: 12 months + 12 months **Position Overview**: **Key Responsibilities**: - Collaborate closely with interdisciplinary teams to analyze and interpret security assessment outcomes, furnishing actionable recommendations for remediation. - Remain abreast of the latest cybersecurity trends, tools, and...


  • Remote, India Willware Technologies Full time

    **Cybersecurity Penetration Tester R&D** **Company Name: Product-Based Company** **Work Mode: Onsite / Fulltime** **Work Location - Bangalore** **Experience: 5 Years** **Job Description Overview**: ▪ Lead engagements from kickoff with product owners through scoping engagements, penetration testing and reporting while adhering to the agreed scope and...


  • Remote, India Willware Technologies Full time

    Cybersecurity Penetration Tester R&DCompany Name: Product-Based CompanyWork Mode: Onsite / FulltimeWork Location - BangaloreExperience: 5 YearsJob Description Overview: Lead engagements from kickoff with product owners through scoping engagements, penetration testing and reporting while adhering to the agreed scope and deadlines. Minimum 3+ years of...

  • Penetration Tester

    3 weeks ago


    Remote, India Willware Technologies Full time

    **Company Name: Product-Based Company** **Work Mode: Onsite / Fulltime** **Work Location - Bangalore** **Experience: 3+ Years** **Job Description Overview**: ▪ Lead engagements from kickoff with product owners through scoping engagements, penetration testing and reporting while adhering to the agreed scope and deadlines. ▪ Minimum 3+ years of...

  • Vapt Tester-remote

    2 months ago


    Remote, India TeamPlus Staffing Solution Pvt Ltd Full time

    The Penetration tester must have CREST accreditation status in order to qualify for the Project. Penetration tester must hold minimum 2 of the following qualifications or equivalent. Offensive Security Certified Professional (OSCP) Certified Information Systems Security Professional (CISSP) Offensive Security Certified Wireless Professional (OSWP) CREST...

  • Vapt Tester-remote

    2 weeks ago


    Remote, India TeamPlus Staffing Solution Pvt Ltd Full time

    The Penetration tester must have CREST accreditationstatus in order to qualify for the Project. Penetration testermust hold minimum 2 of the following qualifications orequivalent.Offensive Security Certified Professional (OSCP)Certified Information Systems Security Professional(CISSP)Offensive Security Certified Wireless Professional(OSWP)CREST Practitioner...

  • Penetration Tester

    3 weeks ago


    Remote, India Shaeryl Data Tech Pvt Ltd Full time

    **Key Skills**: Proficiency in using security tools like Burp Suite, Metasploit, Nessus, Wireshark, etc. **Key Responsibilities**: 1. Vulnerability Assessment: - Use a variety of automated tools and manual techniques to identify vulnerabilities. - Prioritize vulnerabilities based on risk and potential impact. 2. Penetration Testing: - Develop custom...

  • Penetration Tester

    2 weeks ago


    Remote, India NexusCrypt Full time

    **About NexusCrypt** We're not your typical security company. We're a team of enthusiastic cybersecurity professionals dedicated to empowering businesses to navigate the ever-changing threat landscape. We achieve this by offering a comprehensive suite of penetration testing services, essentially acting as ethical hackers to identify and fix vulnerabilities...

  • Penetration Tester

    3 weeks ago


    Remote, India Shaeryl Data Tech Pvt Ltd Full time

    **Key Skills**: Proficiency in using security tools like Burp Suite, Metasploit, Nessus, Wireshark, etc. **Key Responsibilities**: 1. Vulnerability Assessment: - Use a variety of automated tools and manual techniques to identify vulnerabilities. - Prioritize vulnerabilities based on risk and potential impact. 2. Penetration Testing: - Develop custom...

  • Penetration Tester

    3 weeks ago


    Remote, India Verve Group Full time

    **Who We Are** **Who You Are** Become a Digital Guardian: Attack Our Critical Assets We're seeking a passionate information security pentester to join our team. You'll be on the front lines, safeguarding our sensitive data and systems from ever-evolving threats in the digital landscape. Here's what you'll bring to the table: - A keen mind for security:...

  • Penetration Tester

    2 weeks ago


    Remote, India Claranet Full time

    About The Role:The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer's external attack surface...


  • Remote, India SeerTech Systems Full time

    Total experience :2-4yrs CTC offered : up to 7 lpa Mode of operation: Remote (Work from home) Roles and Responsibilities: - Skills required - Good understanding of OWASP TOP 10. - Hand on experience - Burpsuite, frida, mobexler, APKtool etc. - Analyze scan reports and suggest remediation and mitigation plan. **Job Types**: Full-time,...

  • Penetration Tester

    2 weeks ago


    Remote, India Claranet Full time

    **About The Role**: The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack...

  • Tester

    3 weeks ago


    Remote, India Blupace Full time

    About the job Why join us? Blupace is a world-class IT development company that strives to improve its processes constantly. The company has been in business since 2008 and employs over 160+ people in more than 4 countries. Blupace provides innovative software solutions for businesses of all sizes, with a focus on Web & Mob Applications, e-commerce...