Penetration Tester

2 days ago


Bengaluru, India Shell Full time

**The Role**:
**Where you fit in?**

The purpose of the IRM Function is to ensure that Shell is addressing Information Risks in an effective and efficient manner, commensurate with Shell risk appetite, and being seen as an industry leader among peers and key suppliers of security services.The Information Risk posture of Shell includes a wide variety of potential business impacts, such as HSSE impacts, production loss, financial and maintenance operations loss, loss of Most Confidential bidding data. The IRM Function defines requirements for the assessment of Information Risks, defines the selection of mandated IT Controls, and defines and executes assessments of the design and operational effectiveness of these controls. The function organises communication campaigns to impact the behaviour of business and IT staff where it relates to Information Risks.In addition to these preventative measures, the IRM Function includes a Cyber Resilience function to understand the cyber threat landscape and the vulnerabilities to cyberattacks in IT systems and services, to detect malicious behaviour and to respond to incidents.

**What's** the role?**

As part of the Information Risk Management function, the CyberDefence capability has specific focus on identifying cyber threats, discovery of IT vulnerabilities, monitoring for cyber intrusions and response to security incidentsAs part of the CyberDefence capability the Penetration testing team has the following main areas of focus:

- To find major vulnerabilities in IT landscapes where Shell data is hosted before they are being exploited for malicious purposes.
- To prioritize and help remediate vulnerabilities as soon as possible where required.

A Penetration tester in this team you are responsible:

- To plan, scope, execute and report on attack & penetration tests on new IT developments and hypothetical threat scenarios.
- To close high risk vulnerabilities as soon as possible and register other vulnerabilities for risk priorization and remediation where required.

**Accountabilities**

**Penetration Testing**
- Support the Vulnerability Lead in planning penetration tests based on new IT developments and hypothetical threat scenarios and find appropriate budget and sponsors.
- Scope the tests in more detail and find information on network address and accounts.
- Where necessary to help find additional expertise necessary to execute the tests.
- Execute the tests preventing Business disruption as much as possible.
- Report on findings, fixing high risk vulnerabilities as soon as possible and registering other vulnerabilities for later risk priorization and remediation where required.

**Vulnerability Scanning**
- Operate periodic vulnerability scanning tools and services such as Nexpose, Veracode and others.
- Support the Vulnerability Lead in consolidating the vulnerability scanning tools where possible.
- Integrate reporting with other CyberDefence data in IRM workflow system (Collective) and data analytics solution (IRM investigation platform).

**What we need from you?**

Experience and Qualifications required.
- Is a knowledgeable, creative and responsible IT security professional.
- Has excellent analytical skills and appreciates a technical challenge.
- Has a passion for IT technology and is able to share that with other members of the team.
- Has good written and verbal communication skills and provides well-informed advice.
- Produces high quality deliverables in terms of both content and presentation. Examples of deliverables include: reports, presentations and reasoned arguments.
- Demonstrates an understanding of the issues of interest to Shell and proposes viable solutions within the scope of own expertise, taking into account the needs of those affected.
- Maintains knowledge and experience of current practice within own area of expertise and is aware of current developments within own area of expertise.
- Develops and maintains knowledge of Cyber security and maintains an awareness of current developments.
- Promotes transfer of knowledge and awareness of information security to those in related areas.
- Is comfortable working virtually.
- Is able to think and act like a hacker using his creativity to bypass IT defences.
- Has at least 1 year experience in IT security and preferably experience in attack and penetration testing/ethical hacking or technical IT audits.
- Has a solid understanding of IT networks and operating systems such as Windows and Unix/Linux.
- Has experience with analysing network traffic using tools such as tcpdump, wireshark.
- Has experience using open source scanning tools such as nmap, nessus, metasploit and/or commercial tools such as Rapid7, Quallys.
- Has experience with scripting tools and programming languages such as Perl, Python, C, C++, VBS, Java and analytical and reporting tools such as Excel, Sharepoint and preferably Splunk.
- Has relevant certifications such as, CISSP, SANS and preferably:

- GIAC Penetration Tester


  • Penetration Tester

    4 days ago


    Bengaluru, Karnataka, India Utthunga Full time

    Role: Penetration TesterExperience: 3- 5 yearsLocation: BangaloreSkills: Penetration Tester, Pen Tester, Cyber securityNotice period: Immediate- 15 days joinerRoles and Responsibilities· Test and operate security controls for various applications in compliance with the prescribed cybersecurity standards in place.· Collaborate with software architects to...

  • Penetration Tester

    4 days ago


    Bengaluru, Karnataka, India Utthunga Full time

    Role: Penetration Tester Experience : 3- 5 years Location: Bangalore Skills: Penetration Tester, Pen Tester, Cyber security Notice period: Immediate- 15 days joiner Roles and Responsibilities · Test and operate security controls for various applications in compliance with the prescribed cybersecurity standards in place. · Collaborate with software...

  • Penetration Tester

    3 days ago


    Bengaluru, Karnataka, India SSquad Global Full time

    **We're Hiring: Penetration Tester _ Bangalore (Immediate Joiner)** **Location**: Bangalore (Work from Office, 5 Days) **Experience**: 3+ Years **Availability**:Immediate Joiners Only** **Interview Mode**: Virtual Ssquad Global is seeking a skilled and passionate **Penetration Tester** to join our cybersecurity team at our Bangalore office. If you're a...

  • Penetration Tester

    2 days ago


    Bengaluru, India CIEL HR Services Full time

    **ROLE** :.penetration tester Experience : 3 - 7 Years Location : Chennai **Work Location - DLF, Chennai - Work from Office **Alternative saturday working** Security Test Engineer: - Understand the non-functional requirements from business. - Experience in Analyzing and identifying the vulnerabilities manually. - Experience in Web Application & Mobile...

  • Penetration Tester

    4 weeks ago


    Navi Mumbai, Bengaluru, Delhi NCR, India Robotics Technologies Full time

    Job DescriptionDescriptionWe are seeking a skilled Penetration Tester to join our cybersecurity team in India. The ideal candidate will be responsible for identifying and exploiting vulnerabilities in our systems and applications, providing recommendations for improvement, and ensuring the security of our digital assets.Responsibilities- Conduct penetration...


  • Bengaluru, Karnataka, India Delta System & Software, Inc. Full time

    Job Title: Lead Penetration TesterLocation: India (Remote - Travel to Office Once a Month)Job Type: Full-TimeIndustry: Cybersecurity / Information TechnologyWork Hours: Standard IST hoursTravel: Once a month to client/office location (as required)About the Role:We are seeking an experienced and highly skilled Lead Penetration Tester to lead security...

  • Penetration Tester

    6 days ago


    Bengaluru, India Terraeagle Full time

    **Job Brief** We are looking for talented penetration testers who like to break software and embedded devices.In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective and response controls across the global technology landscape. **Responsibilities** - Conduct highly complex...


  • Bengaluru, Karnataka, India Unitforce Technologies Consulting Full time

    Job Description- Core Manual Penetration tester- Hands on security architecture reviews and threat modeling of various applications.- Hands on experience in Threat Modeling- Experience in performing cloud security- Hands on experience in penetration testing- Ethical Hacking- Hands on experience in Threat Modeling- Hands on experience in penetration testing...

  • Penetration Tester

    2 days ago


    Bengaluru, Karnataka, India Resillion Full time

    **Company Description** **_ Resillion is a global company with end-to-end capabilities: no matter your industry, your geographical location, or stage in your digital journey. With offices in North America, Europe, and Asia, Resillion will be by your side. Helping you and your organization realize your ambitions in cyber security, testing of digital media...


  • Bengaluru, Karnataka, India Saviynt Full time

    Saviynt is an identity authority platform built to power and protect the world at work In a world of digital transformation where organizations are faced with increasing cyber risk but cannot afford defensive measures to slow down progress Saviynt s Enterprise Identity Cloud gives customers unparalleled visibility control and intelligence to better...