senior offensive security analyst

3 weeks ago


Pune, Maharashtra, India Spectral Consultants Full time
Job Description

Job Description

ESSENTIAL JOB FUNCTIONS:

- Typical daily work will consist of performing advanced penetration tests on cloud-based and on-premises infra to identify security weaknesses and loopholes.
- Perform Red teaming / Adversary emulations to simulate sophisticated cyberattacks and assess the effectiveness of existing security controls.
- Conduct Purple team exercises in collaboration with Sec-Ops to assess the effectiveness of defensive measures and incident response capabilities through realistic attack simulation.
- Develop and test custom exploits to demonstrate vulnerabilities and assess the potential impact on systems.
- Execute social engineering attacks, such as phishing or vishing, to evaluate the organization's susceptibility to human-centric threats.
- Perform Breach and Attack Simulations using BAS platform across the organization infrastructure.
- Conduct comprehensive cloud penetration tests targeting AWS, Azure, GCP to identify and exploit misconfigurations, insecure interfaces, and vulnerabilities in cloud services and applications.
- Assess and exploit weak IAM configurations, privilege escalation paths, and over-permissioned roles to identify security risks within cloud environments.
- Collaborate with incident response team to provide insights and support during and after security incidents.
- Regularly review and enhance penetration testing methodologies and practices to adapt to evolving threats and technologies.
- Create detailed reports outlining findings from penetration tests, red team exercises, and vulnerability assessments that include clear, actionable recommendations for remediation and risk mitigation.

MUST HAVE KNOWLEDGE, SKILLS & ABILITIES:

- Proficiency in conducting penetration tests on internal networks, web applications, and systems to identify vulnerabilities and potential attack vectors.
- Ability to simulate sophisticated adversary tactics, techniques, and procedures (TTPs) to mimic real-world cyber-attacks, including social engineering, spear-phishing, and advanced malware deployment.
- Expertise in techniques for lateral movement within a compromised network, including pass-the-hash, RDP hijacking, and privilege escalation. Ability to establish persistence using tools like Cobalt Strike, Empire, or custom scripts.
- Skills in developing and deploying custom malware or payloads to evade traditional security controls like antivirus and endpoint detection and response (EDR) tools.
- Experience with offensive security tools such as Metasploit, Burp Suite, Nmap, Cobalt Strike, Wireshark, and Kali Linux for conducting vulnerability assessments and penetration testing.
- Ability to design and execute social engineering and phishing attacks to assess organizational awareness and vulnerability to human factor exploits.
- Familiarity with common reconnaissance, exploitation, and post exploitation techniques.
- Proficiency in testing web applications for vulnerabilities such as SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF), and other application-level attacks.
- Strong Collaboration, Communication and Interpersonal skills with the ability to collaborate effectively with cross-functional teams, communicate complex technical concepts to non-technical stakeholders, and build consensus around security initiatives.
- Solid understanding of emerging threats, vulnerabilities, and exploits and an ability to think outside the box and emulate adversarial approaches.
- In-depth knowledge of major cloud platforms (AWS, Azure, GCP), including their security models, IAM roles, virtual private cloud (VPC) configurations, and cloud-native security tools.
- Expertise in discovering and exploiting common cloud misconfigurations, including insecure storage buckets, overly permissive IAM roles, and weak security group rules.
- Ability to design cloud-specific threat models and conduct red teaming exercises that simulate advanced attacks on cloud environments to evaluate organizational defenses.
  • Security Analyst

    3 weeks ago


    Pune, Maharashtra, India Exela Technologies Full time

    Job DescriptionGlobal - Risk & Compliance - Senior Security Analyst will play a significant role in our SOX ComplianceDepartment to standardize and operationalize our Regulatory and internal Compliance framework.Job Details:- Role: Global - Risk & Compliance - Senior Security Analyst- Work Location: Pune- Work Type: Work From OfficeResponsibilities:-...

  • Vulnerability Analyst

    4 weeks ago


    Pune, Maharashtra, India University Of Cambridge Full time

    Job DescriptionDuties & Responsibilities:- Analysis, assessment, evaluation, and documentation of incoming issues/security reports from various resources like HackerOne, our penetration testers, customer tickets, and internal tools.- Manage and monitor tools related to the cloud technologies that play a vital role in protecting the organization's and...

  • Security Analyst

    2 days ago


    Pune, Maharashtra, India Exela Technologies Full time

    Job DescriptionGlobal - Risk & Compliance - Senior Security Analyst will play a significant role in our SOX ComplianceDepartment to standardize and operationalize our Regulatory and internal Compliance framework.Job Details:Role: Global - Risk & Compliance - Senior Security AnalystWork Location: PuneWork Type: Work From OfficeResponsibilities:Collaborate...


  • Pune, Maharashtra, India beBeeSecurity Full time

    Job Summary:A comprehensive job that requires meticulous analysis, assessment, and evaluation of security issues. The role involves identifying vulnerabilities in cloud technologies, documenting findings, and collaborating with teams to implement fixes.Responsibilities:Security Analysis: Analyze, assess, and evaluate incoming security reports from various...


  • Pune, Maharashtra, India Accops Full time

    Experience: 5+ years Qualification: MCA/ BE/ BTech / ME/MTech (Preferably in Comp Sc/IT/ Cybersecurity) Technical Skills Required Mandatory: Expertise in web, mobile, and API security with a strong understanding of security-by-design principles. Proficiency in Python, Ruby, PowerShell, Bash, and Perl for security scripting. Solid foundation in network...


  • Pune, Maharashtra, India HackerOne Full time ₹ 25,00,000 - ₹ 28,00,000

    HackerOne is a global leader in offensive security solutions. Our HackerOne Platform combines AI with the ingenuity of the largest community of security researchers to find and fix security, privacy, and AI vulnerabilities across the software development lifecycle. The platform offers bug bounty, vulnerability disclosure, pentesting, AI red teaming, and code...

  • Security Analyst

    2 days ago


    Pune, Maharashtra, India Hitachi Full time ₹ 5,00,000 - ₹ 10,00,000 per year

    Location:Pune, Maharashtra, IndiaJob ID: R0104933Date Posted: Company Name:HITACHI INDIA PVT. LTDProfession (Job Category):OtherJob Schedule: Full timeRemote:NoJob Description:Job Title: Security Analyst - ISA Azure Senitel Designation: Security Analyst Company: Cumulus Systems Pvt. Ltd.Location: Pune, IndiaSalary: As per IndustryCompany...

  • Senior Analyst

    3 weeks ago


    Pune, Maharashtra, India Allianz Full time

    Role : Senior Analyst - Network Engineering ServicesKey Responsibilities :- Network Design & Implementation : Design, configure, and implement complex network solutions based on business requirements, ensuring scalability and security.- Troubleshooting & Support : Act as a final point of escalation for network-related issues, performing advanced...


  • Pune, Maharashtra, India Airtel Digital Full time

    SOC Analyst | JOB Description | Airtel 2 – 6 Years of Experience Role – SOC Analyst – A2 Roles and Requirements The Level 2 SOC Security Analyst is responsible for conducting information security investigations due to security incidents identified from various SOC entry channels (SIEM, Tickets, Email and Phone). Act as a point of escalation in...


  • Pune, Maharashtra, India Snowflake Full time

    Job DescriptionWhere Data Does More. Join the Snowflake team.Snowflake is looking for a Senior Security Risk Analyst to join our Global Security Compliance & Risk team and help manage and improve on the existing program for assessing the risk of third party tools and services in use by Snowflake. You will be responsible for managing the intake process,...