Penetration Testing Staff Engineer
2 days ago
SonicWall is a cybersecurity forerunner with more than 30 years of expertise and is recognized as a leading partner-first company, ensuring our partners and their customers are never alone in the fight against cybercrime. With the ability to build, scale and manage security across the cloud, hybrid and traditional environments in real-time, SonicWall provides relentless security against the most evasive cyberattacks across endless exposure points for increasingly remote, mobile and cloud-enabled users. With its own threat research center, SonicWall can quickly and economically provide purpose-built security solutions to enable any organization—enterprise, government agencies and SMBs—around the world. For more information, visit or follow us on Twitter, LinkedIn, Facebook and Instagram.
Department: Product Security / PSIRT
Overview
As a Staff Penetration Tester within the SonicWall PSIRT, you will assess the security of SonicWall's web applications, firmware, and network security products. This hands-on technical role involves performing end-to-end vulnerability assessments, penetration testing and coordinated vulnerability research across SonicWall's full product ecosystem.
Key Responsibilities:
Penetration Testing & Vulnerability Assessment
- Perform manual and automated penetration testing across web applications, firmware, and network appliances.
- Identify, exploit, and document vulnerabilities across diverse layers — from web interfaces to embedded firmware and network protocols.
- Conduct vulnerability scanning of SonicWall products, VMs, servers, and backend systems
- Execute firmware and binary analysis using tools such as IDA Pro, Ghidra, and binwalk to uncover low-level security flaws.
- Perform web and API pen testing targeting OWASP Top 10 and emerging web vulnerabilities (e.g., SSRF, deserialization, logic flaws).
- Assess firmware update mechanisms, cryptographic implementations, and secure boot processes for tampering or privilege escalation risks.
- Prepare detailed vulnerability reports including exploit paths, root cause analysis, and recommended remediations.
- You will collaborate closely with engineering, QA, and development teams to identify, validate, and mitigate vulnerabilities — ensuring SonicWall products meet the highest standards of security and resilience.
- Support PSIRT investigations, including triage of internally discovered and externally reported vulnerabilities.
- Contribute to tooling, automation, and scripts that enhance penetration testing efficiency and coverage.
- Conduct independent research on novel web, network, and firmware vulnerabilities.
- Develop internal methodologies and knowledge base for consistent test execution across product domains.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Computer or Electrical Engineering, or equivalent experience.
- 5+ years of experience in penetration testing, red teaming, or vulnerability research.
- Strong understanding of network protocols, web application security, and firmware architectures.
- Proficiency with tools such as Burp Suite, Nmap, Nessus, Metasploit, IDA Pro, Ghidra, binwalk, Scapy, Wireshark, and OWASP ZAP.
- Working knowledge of web technologies (HTTP/S, REST, TCP/IP, DNS, SMTP), Linux internals, and scripting languages (Python, Bash, PowerShell).
- Ability to perform source code reviews in C/C++, Java, C#, or Python for security flaws.
- Strong communication skills — capable of presenting technical findings to both engineers and management.
- High attention to detail, strong analytical thinking, and self-driven approach to testing complex environments.
Preferred Qualifications
- Certifications: CEH, OSCP, GPEN, GWAPT, OSWE, GREM, or equivalent.
- Experience with secure development lifecycle (SDLC) integration and DevSecOps automation.
- Familiarity with exploit development, fuzzing frameworks (boofuzz, Peach), or custom test harnesses.
- Understanding of cryptographic mechanisms, secure boot, and firmware validation.
- Prior experience contributing to CVE reporting or vulnerability disclosure programs (VDP/bug bounty).
#LI-NR5
#LI-Hybrid
SonicWall is an equal opportunity employer.
We are committed to creating a diverse environment and are an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
At SonicWall, we pride ourselves on recruiting a diverse mix of talented people and providing active security solutions in 100+ countries.
Applicant Privacy Notice
-
Penetration Testing Staff Engineer
1 week ago
Bengaluru, Karnataka, India SonicWall Full time ₹ 12,00,000 - ₹ 36,00,000 per yearSonicWall is a cybersecurity forerunner with more than 30 years of expertise and is recognized as a leading partner-first company, ensuring our partners and their customers are never alone in the fight against cybercrime. With the ability to build, scale and manage security across the cloud, hybrid and traditional environments in real-time, SonicWall...
-
Bengaluru, Karnataka, India Excellence and Eminence LLP Full time ₹ 12,00,000 - ₹ 36,00,000 per yearWe are looking for a Software Development Engineer Web Penetration with 36Years of Experience for our esteemed clients for Chennai and Bangalore Location.Key Skills: Web Penetration Testing amp; API Testing, Bug Bounty, Burp Suite Labs, Intruders amp; Collaborator, OWASP Testing ASVS, MASVS Checklist, Thick Client, Web, mobile. IOS and Android This is an...
-
Penetration Testing Engineer
1 week ago
Bengaluru, Karnataka, India Grant Thornton Full time ₹ 12,00,000 - ₹ 36,00,000 per year2 - 5 Years1 OpeningBengaluruRole descriptionRole OverviewAs a Penetration Testing Engineer at Grant Thornton, you will conduct advanced security assessments across applications, networks, cloud environments, and enterprise systems. You will emulate real-world attack scenarios, identify vulnerabilities, and collaborate with engineering and client teams to...
-
Penetration Tester
7 days ago
Bengaluru, Karnataka, India Ntech IT Solutions Private Limited Full time ₹ 23,04,000 - ₹ 30,72,000 per yearTitle: Penetration TesterLocation: Bangalore (Hybrid)Job Type: Contract to HireOpenings: Years of exp needed)Must have skills - Offensive Security, Penetration Testing, Red TeamingPosition SummaryWe are seeking an experienced application penetration tester with expertise in both manual and automated testing to join our Security and Privacy Risk Consulting...
-
Web Application Penetration Testing Consultant
2 weeks ago
Bengaluru, Karnataka, India Careernet Full time ₹ 8,00,000 - ₹ 24,00,000 per yearKey Skills: Penetration Testing, Vulnerabilities, Web Application Security, Manual Testing.Roles & Responsibilities:Conduct manual application penetration tests on web applications, internal applications, APIs, and mobile applications to discover and exploit vulnerabilities.Independently research new vulnerabilities in systems and software, modifying and...
-
Penetration Tester
5 hours ago
Bengaluru, Karnataka, India ACL Digital Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob PurposeAs a Senior Penetration Tester, your primary role is to assess and enhance the security of our information systems, networks, and applications through comprehensive penetration testing and vulnerability assessments. You will work closely with our internal product teams to identify weaknesses in their systems and provide actionable recommendations...
-
Bengaluru, Karnataka, India Prudential plc Full time ₹ 12,00,000 - ₹ 36,00,000 per yearPrudential's purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support our...
-
Penetration Tester
7 days ago
Bengaluru, Karnataka, India Happiest Minds Technologies Full time ₹ 8,00,000 - ₹ 12,00,000 per yearSr. Penetration Testing engineerMandatory SkillsPenetration Testing, Web App, Mobile, Web Services/APIs, Network & blockchain.Skill to EvaluatePenetration-TestingExperience4 to 6 YearsLocationBengaluruJob DescriptionMaintain a good relationship with key stakeholders including business, other Application & ISO teams to deliver on security requirements...
-
Penetration Tester
2 days ago
Bengaluru, Karnataka, India Siemens Healthineers Full time ₹ 12,00,000 - ₹ 18,00,000 per yearAre you tired from hacking the same network every single day for the past year? Come and join us in hunting vulnerabilities in a highly dynamic environment. Hundreds of projects are waiting for you.Together we will shape cybersecurity for healthcare. You are welcome to join our team in Bangalore. Your tasks will be the following:Execute penetration tests and...
-
Senior Penetration Tester
2 weeks ago
Bengaluru, Karnataka, India Talent Basket Full time ₹ 12,00,000 - ₹ 30,00,000 per yearNotice- Immediate joiner( Max 15 Days)Candidates Location – Only who are currently available in BangaloreFinal Round – F2FExperience – 8+ YearsSalary – Max- 25 LPAJob title- Senior Penetration TesterAs a Senior Penetration Tester, your primary role is to assess and enhance the security of our information systems, networks, and applications through...