Penetration Testing Engineer

2 days ago


Bengaluru, Karnataka, India Grant Thornton Full time ₹ 12,00,000 - ₹ 36,00,000 per year

2 - 5 Years

1 Opening

Bengaluru

Role description

Role Overview

As a Penetration Testing Engineer at Grant Thornton, you will conduct advanced security assessments across applications, networks, cloud environments, and enterprise systems. You will emulate real-world attack scenarios, identify vulnerabilities, and collaborate with engineering and client teams to remediate risks. This role requires a balance of technical expertise, consulting skills, and strong communication.

Key Responsibilities

  • Plan & Execute Penetration Tests: Perform authorized tests on web applications, APIs, cloud platforms (AWS/Azure/GCP), and internal networks following industry standards (PTES, NIST , OSSTMM).
  • Reporting & Advisory: Deliver clear, actionable reports with risk ratings, exploit narratives, and remediation guidance tailored for technical and executive audiences.
  • Client Engagement: Work directly with clients to scope engagements, explain findings, and advise on secure design and preventive controls.
  • Tooling & Automation: Develop scripts and tools (Python, PowerShell, Bash) to streamline testing and reporting processes.
  • Continuous Improvement: Contribute to internal methodologies, playbooks, and secure SDLC practices; mentor junior team members.
Skills

Required Qualifications

  • Experience: 2–5 years in penetration testing or offensive security.
  • Technical Skills:

  • Web/API testing (OWASP Top 10, ASVS)

  • Cloud security (AWS/Azure/GCP misconfigurations, IAM)
  • Network/Active Directory assessments
  • Familiarity with containers/Kubernetes security

  • Tools: Burp Suite Pro, Nmap, Metasploit, Kali Linux, Wireshark, Nessus/OpenVAS.

  • Scripting: Python, PowerShell, Bash (Go is a plus).
  • Frameworks & Standards: PTES, NIST , MITRE ATT&CK, OWASP.
  • Certifications (Preferred): OSCP, OSWE, OSEP, GPEN, GXPN, eCPPT.

Preferred Qualifications

  • Consulting experience with client-facing communication.
  • Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI DSS).
  • Ability to translate technical findings into business risk language.

Soft Skills

  • Strong communication and presentation skills.
  • Ability to manage multiple engagements and deadlines.
  • Ethical mindset and strict adherence to authorized testing boundaries.
About Grant Thornton INDUS

'Grant Thornton INDUS' comprises GT U.S. Shared Services Center India Pvt Ltd and Grant Thornton U.S. Knowledge and Capability Center India Pvt Ltd. Grant Thornton INDUS is the shared services center supporting the operations of Grant Thornton LLP, the U.S. member firm of Grant Thornton International Ltd. Established in 2012, Grant Thornton INDUS employs professionals across a wide range of disciplines including Tax, Audit, Advisory, and other operational functions. What sets us apart isn't just what we do – it's how we do it. We support and enable the firm's purpose of making business more personal and building trust into every result. We're collaborators – obsessed with quality and ready for anything – who understand the value of strong relationships. Our professionals are well integrated to seamlessly support the U.S. engagement teams, help increase Grant Thornton's access to a wide talent pool, and improve operational efficiencies. Empowered people, bold leadership, and distinctive client service are imbibed in the culture at Grant Thornton INDUS. We are a transparent, competitive, and excellence-driven firm that offers an opportunity to be part of something significant. In addition, professionals at Grant Thornton INDUS serve communities in India through inspirational and generous services to give back to the communities they work in. Grant Thornton INDUS has its offices in two locations in India – Bengaluru and Kolkata



  • Bengaluru, Karnataka, India SonicWall Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    SonicWall is a cybersecurity forerunner with more than 30 years of expertise and is recognized as a leading partner-first company, ensuring our partners and their customers are never alone in the fight against cybercrime. With the ability to build, scale and manage security across the cloud, hybrid and traditional environments in real-time, SonicWall...

  • Penetration Tester

    2 weeks ago


    Bengaluru, Karnataka, India Staffington Global Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Duties and Responsibilities:o Looking atleast 8+ Years of experience in Penetration Testing.o Conduct penetration tests on a wide range of digital products, including networks, web, and mobile applications, to identify vulnerabilities and security weaknesses.o Collaborate with internal product teams to understand their set-ups, goals, and constraints.o...

  • Penetration Tester

    2 weeks ago


    Bengaluru, Karnataka, India emagine Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Assignment descriptionSummary:We are seeking a skilled and detail-oriented Application Security Penetration Tester to join our cybersecurity team. The primary goal of this role is to ensure secure software delivery by planning, executing, and documenting penetration tests on enterprise applications, identifying vulnerabilities, and supporting remediation...


  • Bengaluru, Karnataka, India HSBC Full time

    Some careers shine brighter than others.If you're looking for a career that will help you stand out, join HSBC and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further. HSBC is one of the largest banking and...


  • Bengaluru, Karnataka, India Talent Basket Full time ₹ 12,00,000 - ₹ 30,00,000 per year

    Notice- Immediate joiner( Max 15 Days)Candidates Location – Only who are currently available in BangaloreFinal Round – F2FExperience – 8+ YearsSalary – Max- 25 LPAJob title- Senior Penetration TesterAs a Senior Penetration Tester, your primary role is to assess and enhance the security of our information systems, networks, and applications through...


  • Bengaluru, Karnataka, India Careernet Full time ₹ 8,00,000 - ₹ 24,00,000 per year

    Key Skills: Penetration Testing, Vulnerabilities, Web Application Security, Manual Testing.Roles & Responsibilities:Conduct manual application penetration tests on web applications, internal applications, APIs, and mobile applications to discover and exploit vulnerabilities.Independently research new vulnerabilities in systems and software, modifying and...


  • Bengaluru, Karnataka, India Wabtec Full time ₹ 1,20,000 - ₹ 1,50,000 per year

    It's not just about your career or job title… It's about who you are and the impact you will make on the world. Because whether it's for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow,...


  • Bengaluru, Karnataka, India Clarity Consulting Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Roles & responsibilitiesManage cyber threat management projects and lead day-to-dayred team operations.Plan, scope and conduct complex red team engagements:external/internal network, Active Directory, cloud(AWS/Azure/GCP), web & API, mobile backends, andphysical/social engineering components (phishing, vishing,in-person tests).Conduct comprehensive web & API...

  • Penetration Tester

    2 days ago


    Bengaluru, Karnataka, India SUVIKSAN TECHNOLOGIES PRIVATE LIMITED Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    *About Organization:*Suviksan Technologies is a leading technology services and consulting company, specializing in delivering innovative solutions for complex digital transformation challenges. With over 3+ years of experience managing global enterprises, we proudly serve clients across 4 countries, including India, Germany, Sweden, and the Philippines.Our...

  • Penetration Tester

    1 week ago


    Bengaluru, Karnataka, India Zybisys Consulting Services Full time

    Role OverviewAs Penetration Tester Engineer, you will be responsible for simulating real-world cyberattacks to identify vulnerabilities, assess risks, and improve security defenses. You will work closely with security analysts, DevOps, and IT teams to enhance the organization's resilience against cyber threats.Role & responsibilitiesPerform Web, API, Cloud,...