Cst Associate Penetration Tester

1 week ago


Hyderabad, India Claranet Full time

**About The Role**:
The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack surface for new vulnerabilities, changes in the scope of the attack surface, and proactively inform customers of discovered issues along with recommended remediation; with the overall aim of reducing the lifetime of each vulnerability. Manual testing includes identification of issues which automation alone could not identify, exploitation of all issues, often chaining multiple findings together in order to determine the true impact of vulnerabilities for the customer.
- Manual identification and exploitation of vulnerabilities.
- Manual verification and exploitation of scanner findings.
- Detailed analysis of issues identified and exposure for the customer including proof of concept, reproduction steps, and recommended remediation.
- Communication of findings to the customer in a detailed, accurate and manageable manner both orally and through written vulnerability/scope notifications and periodic summaries.
- Continual professional development to maintain and develop knowledge and technical competencies.
- Maintain professional technical qualifications to demonstrate competency to our clients.
- Undertaking projects and support tasks as appropriate to the role.

**Progression**:

- During mentoring and experience progression, the Associate Penetration Tester will be tasked with- Pre-engagement activities including scoping of assessments and statements of work and determining customer requirements and restrictions.
- On boarding customers into the service including configuration of continual scanning and liaising with customer to resolve issues which may reduce the effectiveness of scanning.
- Monitoring of the customers’ external perimeter for changes, and proactive discovery of new targets to include within the customer’s scope.

**About You**:
**Essential**:

- Excellent written and spoken English including presentation, structure, spelling, and grammar. Along with experience conveying technical information in an accessible manner.
- Core computing skills including but not limited to:

- Networking fundamentals - understanding of OSI Model, TCP/IP, HTTP, DNS, SMB, SMTP and relevant tools.
- Microsoft Windows and Office proficiency along with proficiency in one or more Linux distributions.
- REST APIs, XML and JSON formats.
- Vulnerability identification and exploitation (not limited to OWASP Top 10).
- Experience with common assessment tools such as MITM proxies (e.g. Burp Suite Pro and SQLMap).
- General knowledge of internal and external infrastructure technologies and security assessment including but not limited to:

- Identification and exploitation of misconfigurations or known vulnerabilities in common enterprise infrastructure and services (Windows Domains, Linux servers, virtualisation, databases, switches/routers, etc).
- Knowledge of a scripting language such as Python (preferred), Ruby, PowerShell, or Bash, for the development of new, or editing existing, tools.
- Evidence of rapidly and confidently gaining and knowledge of emerging technologies, vulnerabilities, and penetration testing tools and techniques.
- Excellent time management including setting priorities and goals to complete assigned and arising tasks.

**Desirable**:

- CPSA - CREST Practitioner Security Analyst (or above)
- Public speaking experience
- A related Bachelor’s degree.
- Experience with live bug bounties, particularly where automation has been implemented.
- Knowledge of Open Source Intelligence gathering techniques. Including but not limited to use of Google dorks, DNS, domain registration, certificate transparency, and other public sources of information.

**About Us**:
**About Claranet**

At Claranet, we’re experienced in implementing progressive technology solutions which help our customers solve their epic business challenges. We’re committed to understanding their problems, delivering answers quickly, and making a lasting impact to their business.

We are agile, focused and experienced in business modernisation. Our approach helps customers make genuine, significant shifts in their business strategy, to deliver financial savings, boost innovation, and create a resilient business. We continually invest in our people and the latest technologies, so our customers get peace of mind knowing that they have access to the best talent and services.

In the UK we have over 500 staff working in London, Gloucester, Warrington, Bristol, and Leeds, or as homeworkers.

**Working For Claranet**

Here at Claranet we pride ourselves on going the extra mile for and with our employees (yes, we really mean it). We offer an extensive benefits package that you can tailor to



  • Hyderabad, India Claranet Full time

    **About The Role**: **Department** Sec-1 is a Claranet Group Company, established since 2001 and now providing professional standard Information Security Solutions to over 600 customers across Public and Private sectors. Sec-1 Ltd’s Continuous Security Testing (CST) team is composed of highly skilled penetration testers with a real passion for improving...


  • Hyderabad, India Claranet Full time

    **About The Role**: **Role** The primary function of the Penetration Tester in the CST team is to continually review the customers’ defined scope for vulnerabilities, identify additional targets that should be included in the scope, and report these to the client in a timely, accurate, and comprehensive manner. The Penetration Tester is also responsible...

  • Penetration Tester

    1 day ago


    Hyderabad, Telangana, India Experian Full time

    Full-time Employee Status: Regular Role Type: Hybrid Department: Information Technology & Systems Schedule: Full Time **Company Description**: Experian is the world’s leading global information services company. During life’s big moments — from buying a home or a car to sending a child to college to growing a business by connecting with new...

  • Penetration Tester

    3 weeks ago


    Hyderabad, Telangana, India Castellum Labs Full time

    Job Description This position is for Network and Infrastructure Penetration Testing, NOT AppSec, NOT Web VAPT Castellum Labs is a next-generation cybersecurity technology venture based in Hyderabad, India, with global set of customer base and global ambitions. Our vision is to change the cybersecurity value model in the industry by using custom designed...

  • Penetration Tester

    2 weeks ago


    Hyderabad, India Claranet Full time

    **About The Role**: Claranet Cyber Security is a world class business unit within Claranet, designed to give customers access to market-leading information security services spanning; training, consulting, and managed services. The penetration testing team at Claranet Cyber Security is composed of highly skilled, professional ethical hackers with a real...

  • Penetration Tester

    6 days ago


    Hyderabad, India NTT DATA Full time

    Make an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive. Your day at NTT DATAThe Penetration...


  • Hyderabad, India Claranet Full time

    **About The Role**: Claranet Cyber Security is a world class business unit within Claranet, designed to give customers access to market-leading information security services spanning; training, consulting, and managed services. The penetration testing team at Claranet Cyber Security is composed of highly skilled, professional ethical hackers with a real...

  • Penetration Testing

    17 hours ago


    Bengaluru, Hyderabad, Pune, India Infosys Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Technical skills:Network penetration testing and manipulation of network infrastructureMobile and/or web application assessmentsEmail, phone social-engineeringShell scripting or automation of simple tasks using Python, Ruby, Bash and PowerShellDeveloping, extending, or modifying exploits, shellcode or exploit toolsStrong knowledge of tools used for wireless,...

  • Tester

    2 weeks ago


    Hyderabad, India Digitowork Full time

    **JD for Software Tester** Result driven s/w tester to be responsible for designing and running tests on software usability. He will conduct tests, analyze the results, and report observations to the design team. He should possess working knowledge of software and test design, the capability to run through tests, and the ability to analyze the results....


  • Hyderabad, Telangana, India beBeeCybersecurity Full time ₹ 20,00,000 - ₹ 25,00,000

    Job Title: Cybersecurity Expert, Penetration TesterJob Description:Conduct thorough penetration testing engagements to assess web applications and software security.Develop strategic attack plans to simulate real-world threats and identify vulnerabilities.Deliver in-depth security assessments and provide actionable recommendations to enhance the...