Join Tsaaro as a Senior Penetration Tester
Hack with Purpose. Strengthen Security. Build Cyber Resilience.
Are you passionate about offensive security, ethical hacking, and helping organizations identify and eliminate security vulnerabilities before attackers can exploit them?
At Tsaaro, we go beyond vulnerability identification—we help organizations proactively strengthen their cybersecurity posture through comprehensive Vulnerability Assessment and Penetration Testing (VAPT), Red Team exercises, cloud security assessments, and offensive security consulting. We are looking for a Senior Penetration Tester who thrives in consulting environments, enjoys solving complex security challenges, and can deliver practical, risk-based security solutions to clients.
About Tsaaro
At Tsaaro, privacy and cybersecurity are at the heart of everything we do. Our team of cybersecurity specialists and privacy consultants works closely with organizations to identify vulnerabilities, assess cyber risks, strengthen security controls, and build resilient cyber defense programs.
Our consulting approach focuses on delivering practical, business-aligned cybersecurity solutions that help clients secure critical assets, reduce cyber risk, achieve compliance, and stay ahead of evolving threats.
Your Role: Senior Penetration Tester
As a Senior Penetration Tester, you will lead and execute Vulnerability Assessment and Penetration Testing (VAPT) engagements across web applications, APIs, mobile applications, networks, cloud environments, and enterprise infrastructure. You will work closely with clients to identify exploitable vulnerabilities, simulate real-world attack scenarios, validate security controls, and provide actionable remediation recommendations to strengthen their overall cybersecurity posture.
Key Responsibilities
-
Conduct end-to-end Vulnerability Assessment and Penetration Testing (VAPT) across web applications, APIs, mobile applications, internal and external networks, cloud environments, and enterprise infrastructure.
-
Perform manual penetration testing to identify and validate security vulnerabilities beyond automated vulnerability scans.
-
Conduct security assessments aligned with industry methodologies such as OWASP Testing Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
-
Identify and exploit vulnerabilities including OWASP Top 10, OWASP API Security Top 10, authentication and authorization flaws, business logic vulnerabilities, insecure configurations, privilege escalation, and infrastructure weaknesses.
-
Perform internal and external network penetration testing, Active Directory assessments, wireless security testing, and cloud security assessments across AWS, Microsoft Azure, and Google Cloud Platform.
-
Execute Red Team assessments, adversary emulation exercises, and attack simulations where required.
-
Validate and prioritize vulnerabilities based on business impact, exploitability, and risk.
-
Prepare detailed technical reports, executive summaries, proof-of-concept documentation, and actionable remediation recommendations.
-
Support clients in vulnerability remediation by performing re-validation testing and security consultations.
-
Mentor junior penetration testers and contribute to the continuous improvement of internal methodologies, tools, automation scripts, and offensive security playbooks.
-
Stay updated on emerging cyber threats, attack techniques, exploit research, and security vulnerabilities to continuously enhance testing methodologies.
-
Collaborate with cross-functional teams to improve secure development practices, strengthen security controls, and enhance clients' overall cybersecurity resilience.
-
3–6+ years of experience in Penetration Testing, Vulnerability Assessment (VAPT), Offensive Security, Red Teaming, or Cybersecurity Consulting.
-
Strong hands-on experience in web application, API, mobile application, network, cloud, and infrastructure penetration testing.
-
Deep understanding of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK Framework, PTES, NIST SP 800-115, and common penetration testing methodologies.
-
Hands-on experience with offensive security tools such as Burp Suite Professional, Metasploit, Nmap, Nessus, Wireshark, SQLMap, BloodHound, Impacket, Nuclei, Kali Linux, and similar tools.
-
Experience conducting security assessments across AWS, Microsoft Azure, and Google Cloud Platform.
-
Strong understanding of networking protocols, Windows and Linux security, Active Directory, authentication mechanisms, and secure application architecture.
-
Experience preparing technical penetration testing reports, executive summaries, and remediation guidance for clients.
-
Excellent analytical, problem-solving, stakeholder management, and client communication skills.
-
Professional certifications such as OSCP, OSEP, OSWE, PNPT, GPEN, CEH Practical, CRTO, or equivalent offensive security certifications are highly preferred.
-
A collaborative, research-driven, and solution-oriented mindset with the ability to independently manage multiple client engagements.
Why Join Tsaaro?
-
Work with one of India's fastest-growing privacy and cybersecurity consulting firms.
-
Gain exposure to global clients across diverse industries.
-
Lead advanced penetration testing and offensive security engagements.
-
Accelerate your career with mentorship and leadership opportunities.
-
Hybrid work flexibility.
-
Continuous learning support through certifications and professional development programs.
From the Tsaaro Team
"At Tsaaro, we believe the strongest security programs are built by continuously challenging them. If you're passionate about offensive security, uncovering hidden risks, and helping organizations strengthen their cyber resilience, we'd love to have you on our team."
Ready to Advance Your Cyber Security Career?
Apply now and become part of Tsaaro's mission to build secure, resilient, and compliant organizations.