Experience: 1-2 Years
Location: Noida Sector 125
Key Responsibilities:
- Perform end-to-end penetration testing (black-box, gray-box, white-box) on:
- Web applications
- REST/GraphQL APIs
- Mobile applications (Android/iOS)
- Internal and external infrastructure
- Active Directory environments
- Thick client and thin client applications
- Identify and exploit vulnerabilities such as:
- OWASP Top 10 (Web & API)
- Authentication & authorization bypass
- Business logic flaws
- SSRF, deserialization, IDOR, RCE
- Infrastructure misconfigurations
- Privilege escalation & lateral movement in AD
- Conduct Active Directory security assessments, including:
a. OWASP Top 10 (Web & API)
b. Authentication & authorization bypass
c. Business logic flaws
d. SSRF, deserialization, IDOR
e. Infrastructure misconfigurations
- Perform infrastructure penetration testing:
a. Network enumeration and exploitation
b. Firewall/WAF bypass techniques
c. VPN security assessment
d. Cloud misconfiguration testing (if applicable)
- Conduct mobile application security testing:
a. Static and dynamic analysis
b. SSL pinning bypass
c. Insecure storage testing
d. Runtime manipulation
- Perform thick client security testing:
a. Binary analysis
b. Traffic interception
c. Local privilege testing
d. Insecure deserialization and logic abuse
- Conduct basic reverse engineering:
a. Analyze binaries using tools like IDA/Ghidra
b. Identify hardcoded secrets, insecure crypto, and logic flaws
c. Modify application behavior for security validation
- Develop proof-of-concept exploits to demonstrate impact
- Prepare detailed technical reports including risk ratings (CVSS), exploitation steps, and remediation guidance
- Conduct re-testing to validate remediation fixes
- Collaborate with developers, infrastructure, and DevOps teams to remediate vulnerabilities
- Stay current with emerging exploit techniques, attack frameworks, and offensive security research
Required Skills & Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or related field
- 1–2 years of hands-on experience in penetration testing or offensive security
- Strong understanding of:
a. TCP/IP, DNS, VPNs, Firewalls
b. Authentication protocols (NTLM, Kerberos, OAuth, JWT)
c. Web technologies (HTTP/HTTPS, sessions, cookies, CORS)
- Hands-on experience with tools such as:
a. Burp Suite (Professional preferred)
b. Nmap
c. Metasploit
d. BloodHound
e. Mimikatz
f. Wireshark
g. Postman (API testing)
h. MobSF / Frida (mobile testing)
a. Windows & Linux privilege escalation techniques
b. Active Directory attack methodologies
c. Web proxying and traffic interception
d. Manual vulnerability validation beyond automated scans
- Strong analytical, exploitation, and troubleshooting skills
- Ability to think like an attacker and chain vulnerabilities
- Strong technical documentation and reporting skills
- Effective communication and stakeholder presentation skills
- Mandatory certifications such as:
- CEH/eJPT
Pay: ₹500,000.00 - ₹600,000.00 per year
Work Location: In person