Penetration Tester

1 day ago


Mumbai, Maharashtra, India BNP Paribas Full time ₹ 15,00,000 - ₹ 25,00,000 per year

About Business line/Function:

ITG provides testing services for the BNP Paribas Group. The Security testing team is responsible to execute SAST, Penetration Tests (Black or Gray Box) for the Web and Mobile applications pertaining to the group

Responsibilities

Direct Responsibilities

  • To perform Penetration testing (Gray Box and/or Black Box) for Web applications, Mobile, API, and thick client applications.
  • Hands-on mobile penetration tester with strong knowledge and experience in Android and iOS application security testing (both static and dynamic), responsible for discovering, validating and reporting security issues in mobile applications.
  • Perform Static analysis (SAST) and Dynamic analysis (DAST) on Android APKs and iOS IPA to identify insecure storage, hardcoded secrets, insecure configurations, runtime hooking, parameter tampering etc
  • Conduct reverse engineering and protection bypass on mobile applications including decompiling /inspecting binaries, analyzing native libraries ) and bypassing client-side protections (root / jailbreak detection, SSL pinning, obfuscation, tamper checks etc.) using tools like Frida, objection magisk, cydia/selio/zebra and Xposed.
  • Strong research knowledge and should be updated with evolving mobile threats and industry standard (OWASP MASVS/MASTG)
  • To understand the applications security requirements and identify & document the scope of the test.
  • Ensure execution of the documented security scenarios for the application under test.
  • Document and report all findings.
  • Collaborate with the developers to help them understand the vulnerabilities reported in application.
  • Escalate issues to the local management and onshore stakeholders in case it affects the testing progress.
  • Ensure processes for the project is followed for the assessments.
  • Note: Mandatory requirement Mobile, Web & API Penetration Testing
  • Optional: Experience in Source Code Assessment (SCA)/SAST.

Technical & Behavioral Competencies

  • Clear understanding of OWASP Top 10 - application security risks
  • Tools/OS: Burp Suite, OWASP ZAP, Kali Linux, mobsf, jadx, dex2jar, adb, xcode, Frida, objection, apktool, putil, otool.
  • Manual Security Testing & Analysis, Security Test Designing
  • Excellent Interpersonal and presentation skills
  • Strong in verbal and written communication
  • Good analytical skills
  • Strong Time Management
  • Must be flexible, independent, self-motivated.
  • Team player

Specific Qualifications(if required)

CSSLP/CEH or equivalent certification preferred

Education Level: 

Bachelors degree or equivalent.

Experience Level

At least 3 years of relevant experience.


  • Penetration Tester

    2 weeks ago


    Mumbai, Maharashtra, India DigiFortex Full time ₹ 5,00,000 - ₹ 10,00,000 per year

    Company DescriptionDigiFortex is an emerging Cyber Security startup recognized by the Govt. of Karnataka and Silicon India. The company is ISO 27001 certified and empanelled by CERT-In for Information Security Auditing Services. DigiFortex operates globally, focusing on Advanced Penetration Testing (VA/PT), Managed Security Services (MSSP), Security...


  • Mumbai, Maharashtra, India Suzva Software Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Level 3 Resource Application Penetration Tester (APT) Skills: Advanced Application Penetration Testing (Web/Mobile/API), BurpSuite, MIS Reporting, Certifications (CEH/OSCP/SANS25/LPT/CEPT)Application Penetration Tester (APT)(Web/Mobile/API), BurpSuite, MIS Reporting, Certifications (CEH/OSCP/SANS25/LPT/CEPT)

  • Penetration Tester

    2 weeks ago


    Mumbai, Maharashtra, India Presidio Information Risk Management LLP Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Role Overview: As a Penetration Tester at Presidio Information Risk Management LLP (PIRM) located in Pune, you will have a full-time hybrid role with the flexibility to work from home on some occasions. Your main responsibility will be to conduct security assessments on applications, infrastructure, and networks. This includes performing vulnerability...

  • Penetration Tester

    2 weeks ago


    Mumbai, Maharashtra, India Yethi Consulting Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Job DescriptionRole: Penetration TesterLocation: Mumbai (Work from Office)Experience: 5+ YearsKey Responsibilities:Conduct advanced application-level penetration tests on both thick client and web-based applications.Perform dynamic analysis and manual testing with strong expertise in Burp Suite.Stay updated with the latest vulnerabilities, exploits, and...

  • Penetration Tester

    2 weeks ago


    Mumbai, Maharashtra, India ISECURION Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Job Title:Penetration TesterLocation:Thane MumbaiExperience:6+ Years in Information Security DepartmentNotice Period:ImmediateJob Summary:We are seeking a highly skilled and creative Penetration Tester with over 6 years of experience to join our Offensive Security team. The successful candidate will have deep expertise in identifying vulnerabilities in...


  • Mumbai, Maharashtra, India Suzva Software Technologies Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Skills: Advanced Application Penetration Testing (Web/Mobile/API), BurpSuite, MIS Reporting, Certifications (CEH/OSCP/SANS25/LPT/CEPT)Job Overview:The Application Penetration Tester will be responsible for conducting in-depth security assessments of web, mobile, and API applications to identify vulnerabilities, assess risks, and recommend effective...

  • Penetration Tester

    2 weeks ago


    Mumbai, Maharashtra, India Vigilant Telecom Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Company DescriptionVigilant Telecom operates with tactical precision under the tagline,"Infiltrate. Expose. Neutralize."We provide elite cybersecurity services, focusing on penetration testing for networks, web and mobile applications, APIs, and cloud environments. Our vulnerability assessments prioritize weaknesses often overlooked by others. We offer rapid...


  • Mumbai, Maharashtra, India Shashwath Solution Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    We are seeking an experienced and highly skilled Penetration Tester with expertise in mobile application security, specifically for both Android and iOS platforms. As a Senior Penetration Tester, you will be responsible for identifying and exploiting vulnerabilities in mobile applications, networks, APIs, and other critical systems. Your primary...

  • Penetration Tester

    4 weeks ago


    Mumbai, Maharashtra, India Alp Consulting Ltd. Full time

    Experience: MAX 5 to 12 YrsLocation: HYD/MUM/CHNRequirementsEducation: B.E. / B. Tech/M.E. /M. TechCertifications, If Any: GWAPT, CEH, OSCP, SANS, CEHFoundational Skills:· Strong hands-on experience in conducting comprehensive manual penetration tests and source code reviews against web, API, mobile applications, services, platforms, systems, and networks...

  • Penetration Tester

    4 weeks ago


    Mumbai, Maharashtra, India Alp Consulting Ltd. Full time

    Experience: MAX 5 to 12 Yrs Location: HYD/MUM/CHN Requirements Education: B.E. / B. Tech/M.E. /M. Tech Certifications, If Any: GWAPT, CEH, OSCP, SANS, CEH Foundational Skills: · Strong hands-on experience in conducting comprehensive manual penetration tests and source code reviews against web, API, mobile applications, services, platforms, systems, and...