Penetration Tester

3 days ago


Hyderabad, India Claranet Full time

**About The Role**:
**Role**

The primary function of a Penetration Tester in the Continuous Security Testing (CST) team is to continually review the customers’ defined scope for vulnerabilities, identify additional targets that should be included in the scope, and report these to the client in a timely, accurate, and comprehensive manner. Penetration Testers are also responsible for pre-engagement activities including scoping, statements of work, working with customers to determine their testing requirements and restrictions, and on boarding customers into the service.

**Essential duties & responsibilities**:
The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack surface for new vulnerabilities, changes in the scope of the attack surface, and proactively inform customers of discovered issues along with recommended remediation; with the overall aim of reducing the lifetime of each vulnerability. Manual testing includes identification of issues which automation alone could not identify, exploitation of all issues, often chaining multiple findings together in order to determine the true impact of vulnerabilities for the customer.
- Pre-engagement activities including scoping of assessments and statements of work, and determining customer requirements and restrictions.
- On boarding customers into the service including configuration of continual scanning, and liaising with customer to resolve issues which may reduce the effectiveness of scanning.
- Monitoring of the customers’ external perimeter for changes, and proactive discovery of new targets to include within the customer’s scope.
- Manual identification and exploitation of vulnerabilities.
- Manual verification and exploitation of scanner findings.
- Detailed analysis of issues identified and exposure for the customer including proof of concept, reproduction steps, and recommended remediation.
- Communication of findings to the customer in a detailed, accurate and manageable manner both orally and through written vulnerability/scope notifications and periodic summaries.
- Assisting in the continual development of the team and service through research and development activities. This includes the development of in-house tools the implementation of tools released to the community, and design and documentation of new and existing internal systems and processes.
- Continual professional development to maintain and develop knowledge and technical competencies.
- Maintain professional technical qualifications to demonstrate competency to our clients.
- Contributing to the writing and publishing of whitepapers and advisories.
- Undertaking projects and support tasks as appropriate to the role.

**About You**:
**Position specifications**

**Essential**:

- Excellent written and spoken English including presentation, structure, spelling, and grammar. Along with experience conveying technical information in an accessible manner.
- Core computing skills including but not limited to:

- Networking fundamentals - understanding of OSI Model, TCP/IP, HTTP, DNS, SMB, SMTP and relevant tools.
- Microsoft Windows and Office proficiency along with proficiency in one or more Linux distributions.
- REST APIs, SOAP APIs, XML and JSON formats.
- Vulnerability identification and exploitation (not limited to OWASP Top 10).
- Experience with common assessment tools such as MITM proxies (e.g. Burp Suite Pro) and SQLMap.
- Good knowledge of internal and external infrastructure technologies and security assessment including but not limited to:

- Identification and exploitation of misconfigurations or known vulnerabilities in common enterprise infrastructure and services (Windows Domains, Linux servers, virtualisation, databases, switches/routers, etc).
- Windows and Linux Sandbox/Desktop Breakout.
- Knowledge of a scripting language such as Python (preferred), Ruby, PowerShell, or Bash, for the development of new, or editing existing, tools.
- Excellent time management including setting priorities and goals to complete assigned and arising tasks.

**Desirable**:

- Knowledge of Open Source Intelligence gathering techniques. Including but not limited to use of Google dorks, DNS, domain registration, certificate transparency, and other public sources of information.
- Experience with live bug bounties, particularly where automation has been implemented.
- Knowledge of security considerations in the cloud (AWS, Azure, and GCP), particularly identifying vulnerable configurations through management and API access along with exploitation of web/infrastructure vulnerabilities specific to cloud environments.

**Desirable Certifications**:

- CRT - CREST Registered Penetration Tester (or above).
- OSCP - O


  • Penetration Tester

    6 days ago


    Nanakramguda, Hyderabad, Telangana, India Vatins Systems PVT LImited Full time

    **Penetration Tester** **Location**: On Site (Hyderabad) **Experience**: 3+ years **Certifications**: OSCP/CRTP (mandatory) We have an opening for a Penetration Tester to join our team and help our development initiatives. This is a great opportunity for aspiring Penetration Tester’s to obtain practical experience and make a meaningful...


  • Hyderabad, India RSM US LLP Full time

    The Penetration Tester conducts tests and purposefully attempts to exploit existing computer systems and software to detect and correct weaknesses. The Penetration Tester must have experience with tools used to perform Dynamic Application Security Testing (DAST) along with an understanding of common software security issues and remediation techniques (OWASP...

  • Penetration Tester

    4 weeks ago


    Hyderabad, Telangana, India Awign Full time

    Only Immediate Joiner- Within 8-10 days5+ YearsRotational ShiftHyderabad, IND (ONSITE)Job Responsibilities:• Conducting and coordinating comprehensive Attack Surface Discovery, Penetration tests andCloud on system and network levels, employing advanced ethical hacking techniques. • Application Penetration Testing (Browser-based, API, Mobile, IoT)•...


  • Hyderabad, Telangana, India Amgen Inc Full time

    Job DescriptionRoles & Responsibilities:- Develop and implement the penetration testing strategy in alignment with Amgen's security framework.- champion a proactive security culture, integrating offensive security principles into Amgen's broader risk management program.- Lead, mentor, and develop a team of penetration testers, fostering a culture of...


  • Hyderabad, Telangana, India ProArch Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    We are hiring a hands-on Penetration Tester to lead and execute end-to-end security assessments across Web, Infrastructure, and Cloud environments. As the technical backbone of our lean and growing VAPT practice, you'll work closely with the Security Lead and directly engage with clients to deliver meaningful, high-impact security outcomes.Key...


  • Hyderabad, Telangana, India beBeeCybersecurity Full time ₹ 21,60,000 - ₹ 31,20,000

    Seeking a seasoned Security Leader to drive proactive security culture and champion secure development practices.Job SummaryWe are seeking a skilled Senior Manager to lead penetration testing efforts, develop strategic capabilities, and foster a culture of innovation and continuous learning.Key ResponsibilitiesDevelop and implement comprehensive penetration...


  • Hyderabad / Secunderabad, Telangana, India beBeeSecurity Full time

    Job SummaryWe are seeking an experienced Security Leader to develop and implement our penetration testing strategy, champion a proactive security culture, and lead a team of penetration testers.The ideal candidate will have a proven track record of leading high-performing security teams, influencing senior collaborators, and driving security adoption across...


  • Hyderabad, Telangana, India beBeeCybersecurity Full time ₹ 1,11,66,000 - ₹ 1,54,22,000

    We are seeking a proactive and technically strong VAPT Professional to join our organization. The ideal candidate should be proficient in scripting and programming, capable of performing secure code reviews, and confident in engaging both technical and non-technical stakeholders.Key ResponsibilitiesDeliver awareness sessions on secure coding, OWASP Top 10,...


  • Hyderabad, Telangana, India beBeeSecurity Full time ₹ 1,20,00,000 - ₹ 1,50,00,000

    Job Title: Security Consultant LeadAbout the Role:We are seeking an experienced and highly skilled security professional to lead security assessments, uncover vulnerabilities, and help build secure digital environments. This is a remote-first role with minimal travel.Key Responsibilities:Lead penetration testing engagements across web, mobile, APIs, cloud,...


  • Hyderabad, Telangana, India Go IT Builders Software Solutions Full time

    We are looking for a Principle/Senior Product Security Engineer located in Hyderabad. The ideal candidate will have the following experience/skillsets but not limited to:Previous experience as a developer preferred "Not a pen tester"Deep understanding of Application securityDeep understanding of securing CI/CD pipelinesExperience with Cloud to include...