Penetration Tester
1 day ago
About Business line/Function:
ITG provides testing services for the BNP Paribas Group. The Security testing team is responsible to execute SAST, Penetration Tests (Black or Gray Box) for the Web and Mobile applications pertaining to the group
Responsibilities
Direct Responsibilities
- To perform Penetration testing (Gray Box and/or Black Box) for Web applications, Mobile, API, and thick client applications.
- Hands-on mobile penetration tester with strong knowledge and experience in Android and iOS application security testing (both static and dynamic), responsible for discovering, validating and reporting security issues in mobile applications.
- Perform Static analysis (SAST) and Dynamic analysis (DAST) on Android APKs and iOS IPA to identify insecure storage, hardcoded secrets, insecure configurations, runtime hooking, parameter tampering etc
- Conduct reverse engineering and protection bypass on mobile applications including decompiling /inspecting binaries, analyzing native libraries ) and bypassing client-side protections (root / jailbreak detection, SSL pinning, obfuscation, tamper checks etc.) using tools like Frida, objection magisk, cydia/selio/zebra and Xposed.
- Strong research knowledge and should be updated with evolving mobile threats and industry standard (OWASP MASVS/MASTG)
- To understand the applications security requirements and identify & document the scope of the test.
- Ensure execution of the documented security scenarios for the application under test.
- Document and report all findings.
- Collaborate with the developers to help them understand the vulnerabilities reported in application.
- Escalate issues to the local management and onshore stakeholders in case it affects the testing progress.
- Ensure processes for the project is followed for the assessments.
- Note: Mandatory requirement Mobile, Web & API Penetration Testing
- Optional: Experience in Source Code Assessment (SCA)/SAST.
Technical & Behavioral Competencies
- Clear understanding of OWASP Top 10 - application security risks
- Tools/OS: Burp Suite, OWASP ZAP, Kali Linux, mobsf, jadx, dex2jar, adb, xcode, Frida, objection, apktool, putil, otool.
- Manual Security Testing & Analysis, Security Test Designing
- Excellent Interpersonal and presentation skills
- Strong in verbal and written communication
- Good analytical skills
- Strong Time Management
- Must be flexible, independent, self-motivated.
- Team player
Specific Qualifications(if required)
CSSLP/CEH or equivalent certification preferred
Education Level:
Bachelors degree or equivalent.
Experience Level
At least 3 years of relevant experience.
-
Penetration Tester
2 weeks ago
Mumbai, Maharashtra, India DigiFortex Full time ₹ 5,00,000 - ₹ 10,00,000 per yearCompany DescriptionDigiFortex is an emerging Cyber Security startup recognized by the Govt. of Karnataka and Silicon India. The company is ISO 27001 certified and empanelled by CERT-In for Information Security Auditing Services. DigiFortex operates globally, focusing on Advanced Penetration Testing (VA/PT), Managed Security Services (MSSP), Security...
-
Application Penetration Tester
2 days ago
Mumbai, Maharashtra, India Suzva Software Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per yearLevel 3 Resource Application Penetration Tester (APT) Skills: Advanced Application Penetration Testing (Web/Mobile/API), BurpSuite, MIS Reporting, Certifications (CEH/OSCP/SANS25/LPT/CEPT)Application Penetration Tester (APT)(Web/Mobile/API), BurpSuite, MIS Reporting, Certifications (CEH/OSCP/SANS25/LPT/CEPT)
-
Penetration Tester
2 weeks ago
Mumbai, Maharashtra, India Presidio Information Risk Management LLP Full time ₹ 9,00,000 - ₹ 12,00,000 per yearRole Overview: As a Penetration Tester at Presidio Information Risk Management LLP (PIRM) located in Pune, you will have a full-time hybrid role with the flexibility to work from home on some occasions. Your main responsibility will be to conduct security assessments on applications, infrastructure, and networks. This includes performing vulnerability...
-
Penetration Tester
2 weeks ago
Mumbai, Maharashtra, India Yethi Consulting Full time ₹ 15,00,000 - ₹ 25,00,000 per yearJob DescriptionRole: Penetration TesterLocation: Mumbai (Work from Office)Experience: 5+ YearsKey Responsibilities:Conduct advanced application-level penetration tests on both thick client and web-based applications.Perform dynamic analysis and manual testing with strong expertise in Burp Suite.Stay updated with the latest vulnerabilities, exploits, and...
-
Penetration Tester
2 weeks ago
Mumbai, Maharashtra, India ISECURION Full time ₹ 20,00,000 - ₹ 25,00,000 per yearJob Title:Penetration TesterLocation:Thane MumbaiExperience:6+ Years in Information Security DepartmentNotice Period:ImmediateJob Summary:We are seeking a highly skilled and creative Penetration Tester with over 6 years of experience to join our Offensive Security team. The successful candidate will have deep expertise in identifying vulnerabilities in...
-
Application Penetration Tester
1 day ago
Mumbai, Maharashtra, India Suzva Software Technologies Full time ₹ 15,00,000 - ₹ 25,00,000 per yearSkills: Advanced Application Penetration Testing (Web/Mobile/API), BurpSuite, MIS Reporting, Certifications (CEH/OSCP/SANS25/LPT/CEPT)Job Overview:The Application Penetration Tester will be responsible for conducting in-depth security assessments of web, mobile, and API applications to identify vulnerabilities, assess risks, and recommend effective...
-
Penetration Tester
2 weeks ago
Navi Mumbai, Maharashtra, India Binary Global Full time ₹ 9,00,000 - ₹ 12,00,000 per yearWe are currently exploring new opportunities in the field ofCybersecurity (Vulnerability Assessment & Penetration Testing – VAPT). With hands-on experience inweb, mobile (Android & iOS), API security testing, and network infrastructure assessments.Key Skills & Experience:VAPT for Web, Mobile, API, and Network InfrastructureSAST & DAST...
-
Application Penetration Tester
2 weeks ago
Mumbai, Maharashtra, India Suzva Software Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per yearKey Responsibilities:Conduct manual and automated security testing of Web, Mobile, and API applications.Perform vulnerability assessments, exploit development, and penetration testing.Use tools such as BurpSuite, OWASP ZAP, Postman, and others for testing and exploitation.Identify, document, and validate security vulnerabilities following OWASP Top 10, SANS...
-
Mumbai, Maharashtra, India Akzac Global Full time ₹ 9,00,000 - ₹ 12,00,000 per yearPerform application penetration testing across web, mobile, and API platforms.Utilize Burp Suite Professional and other industry-standard tools to perform security assessments.Ensure compliance with OWASP Top 10, SANS 25, and other secure coding
-
Application Security Manager
2 weeks ago
Mumbai, Maharashtra, India Yes Bank Full time3-6 years of Experience in the AppSec / Security Testing domainGood conceptual understanding of Application Architecture, Application componentsHandling a team of Security testersGood understanding of OWAPS and other standard and guidelinesWell verse with Red Teaming and Penetration testing activitiesHands on and good knowledge on Application Security...