Senior Penetration Tester
2 days ago
Organization: At CommBank, we never lose sight of the role we play in other people's financial wellbeing. Our focus is to help people and businesses move forward to progress. To make the right financial decisions and achieve their dreams, targets, and aspirations. Regardless of where you work within our organisation, your initiative, talent, ideas, and energy all contribute to the impact that we can make with our work. Together we can achieve great things.
Job Title: Senior Penetration Tester
Location: Bangalore-Manyata Tech Park
Business & Team: The Cyber Security Team protects the bank and our customers from theft, losses and risk events through effective and proactive management of cyber security, privacy and operational risk.
The Security Testing Centre of Excellence (COE) conducts simulated cyber-attacks to ensure systems are safe, sound, and secure by performing security assessments of the Group's technology. This ensures our applications and infrastructure are adequately robust to resist cyber-attacks. Our work seeks to identify security weaknesses using real-world attack scenarios and provide recommendations to assist remediation efforts.
Impact &contribution:
You will lead and perform technical penetration testing activities designed to ensure the bank maintains its risk and security posture at desired levels. You will communicate security issues to both technical and non-technical stakeholders and provide subject-matter expertise across business units. You will mentor junior team members and contribute to the development of innovative solutions to complex technical challenges. This role reports directly to a Centre within the Penetration Testing team.
Roles & responsibilities:
- Lead and conduct security assessments including (but not limited to) web applications, infrastructure, networks, cloud (especially AWS), SaaS, LLM, and mobile applications
- Coordinate small squads of testers in delivering a large programme of testing engagements, using agile methodologies to track progress, and to resolve blockers.
- Carry out scoping and planning activities to determine components to be tested, approach, methodologies, and appropriate levels of test rigour
- Create comprehensive exploitation strategies that identify exploitable technical or operational vulnerabilities to demonstrate business impact and articulate risk.
- Report results of testing and their implications to stakeholders including suppliers, project owners, product crews, and leadership
- Provide technical mentorship and guidance to junior staff
- Maintain awareness of advancements in attack techniques, hardware, software, and other technologies and their implications. Develop new testing methodologies and techniques, contributing to the penetration testing craft across the CoE.
- Ensure all tasks align with internal policies and external regulatory requirements
Essential skills:
- 8+ years of IT Engineering experience.
- Expert-level understanding of vulnerability identification and penetration testing methodologies
- Deep knowledge of software exploitation, security principles, and secure design, with experience conducting penetration testing safely in critical infrastructure environments
- Advanced industry accreditations such as Offensive Security Certified Professional (OSCP), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), or similar are desirable
- Experience in incorporating a broad range of automated tools tools such as Kali Linux, Burp Suite, Metasploit, and others to expand test coverage .
- Ability to develop or recommend analytic approaches to novel problems
- Ability to communicate complex information clearly and confidently
- Tertiary qualifications in Software Engineering, Computer Science, Cyber Security, or a related discipline
- Membership or participation in relevant industry associations
Education Qualification: Bachelor's degree or master's degree in engineering in Computer Science/Information Technology.
If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We're keen to support you with the next step in your career.
We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on
Advertising End Date: 29/11/2025-
Junior Penetration Tester
4 weeks ago
bangalore, India Parrot CTFs Full timeCompany Description Parrot CTFs offers modern cybersecurity training and enterprise-grade consulting through their advanced Capture the Flag (CTF) platform. This platform includes over 150 real-world challenges and vulnerable lab machines, as well as specialized tracks such as Web Exploitation, Active Directory, Digital Forensics, Cryptography, and Reverse...
-
Senior Android Penetration Tester
2 weeks ago
bangalore, India Dminds Solutions Inc. Full timeJob Title: Senior Android Penetration Tester Location: Remote Employment Type: Contract Experience Level: 10+ years (with specialization in Mobile Security) Looking for Immediate Joiners Only Role Overview We are seeking a highly skilled Senior Android Penetration Tester to lead advanced mobile application security testing and vulnerability assessments. The...
-
Senior Android Penetration Tester
2 weeks ago
bangalore, India Dminds Solutions Inc. Full timeJob Title: Senior Android Penetration Tester Location: Remote Employment Type: Contract Experience Level: 10+ years (with specialization in Mobile Security) Looking for Immediate Joiners Only Role Overview We are seeking a highly skilled Senior Android Penetration Tester to lead advanced mobile application security testing and vulnerability assessments. The...
-
Senior Penetration Tester
4 weeks ago
Bangalore, India AppSecure Security Full timeLocation: Fully Remote About Us Appsecure is a leading offensive cybersecurity and red-team services company trusted by Fortune 500s, high-growth startups, and global enterprises. Our team consists of top bug bounty hunters, seasoned red teamers, and security researchers who deliver high-impact security testing across web, mobile, API, and cloud...
-
Senior Penetration Tester
4 weeks ago
Bangalore Urban, India AppSecure Security Full timeLocation: Fully RemoteAbout UsAppsecure is a leading offensive cybersecurity and red-team services company trusted by Fortune 500s, high-growth startups, and global enterprises. Our team consists of top bug bounty hunters, seasoned red teamers, and security researchers who deliver high-impact security testing across web, mobile, API, and cloud...
-
Senior Penetration Tester
4 weeks ago
Bangalore Urban, India AppSecure Security Full timeLocation: Fully Remote About UsAppsecure is a leading offensive cybersecurity and red-team services company trusted by Fortune 500s, high-growth startups, and global enterprises. Our team consists of top bug bounty hunters, seasoned red teamers, and security researchers who deliver high-impact security testing across web, mobile, API, and cloud...
-
Penetration Tester
5 days ago
bangalore, India Brace Infotech Private Ltd Full time4-6 years of penetration testing experience, preferably in highly regulated industries and for global clients • Proficiency with scripting and programming languages • Advanced problem-solving skills • OSCP certification preferred but, GPEN, GWAPT, GXPN, CREST, CESG and similar certifications is a plus • Experience with Cobalt Strike a plus • Strong...
-
Penetration Tester
5 days ago
Bangalore, Karnataka, India Kyndryl Full timeWho We Are At Kyndryl we design build manage and modernize the mission-critical technology systems that the world depends on every day So why work at Kyndryl We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable inclusive world for our employees our customers and our communities The Role Join Kyndryl...
-
Penetration Tester
1 week ago
bangalore, India Teamware Solutions Full timeRoles and Responsibilities:• Perform manual Application penetration testing against API’s (REST/SOAP), Web Applications, Mobile applications, and thick client applications• Perform threat modeling, evaluate application business logic, and perform application architecture reviews• Ability to demonstrate application testing experience in real time via...
-
Penetration Tester
1 week ago
bangalore, India Teamware Solutions Full timeRoles and Responsibilities: • Perform manual Application penetration testing against API’s (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform threat modeling, evaluate application business logic, and perform application architecture reviews • Ability to demonstrate application testing experience in real time...