Job Summary
We are seeking a skilled Ethical Hacker (Penetration Tester) to identify security vulnerabilities across web applications, mobile applications, networks, cloud environments, APIs, and corporate infrastructure. The successful candidate will conduct authorized security assessments, simulate cyberattacks, and provide actionable remediation recommendations to improve our security posture.
Key ResponsibilitiesWeb Application Security Testing
- Perform manual and automated penetration testing.
- Identify vulnerabilities such as:
- SQL Injection
- Cross-Site Scripting (XSS)
- CSRF
- Authentication flaws
- Authorization bypass
- File upload vulnerabilities
- Business logic flaws
Network Security Assessment
- Conduct internal and external network penetration testing.
- Identify misconfigurations and exposed services.
- Assess firewall, VPN, and remote access security.
Mobile Application Security
- Test Android and iOS applications.
- Assess API security.
- Identify insecure data storage and authentication weaknesses.
Cloud Security Assessment
- Evaluate AWS, Azure, and Google Cloud environments.
- Review IAM configurations.
- Identify privilege escalation risks.
Vulnerability Management
- Conduct vulnerability assessments.
- Prioritize findings based on risk.
- Validate remediation efforts.
Reporting
- Prepare detailed penetration testing reports.
- Document vulnerabilities, impact, proof-of-concept, and remediation recommendations.
- Present findings to technical and non-technical stakeholders.
Red Team Activities
- Simulate real-world attack scenarios.
- Conduct phishing awareness assessments.
- Test incident response readiness.
Required SkillsTechnical Skills
- Strong understanding of:
- TCP/IP
- DNS
- HTTP/HTTPS
- Routing and Switching
- Firewalls
- VPNs
Security Knowledge
- OWASP Top 10
- MITRE ATT&CK Framework
- Security Testing Methodologies
- Vulnerability Assessment
Tools
- Burp Suite
- Nmap
- Metasploit
- Nessus
- Wireshark
- Kali Linux
- OWASP ZAP
- Nikto
- SQLMap
Operating Systems
- Linux
- Windows Server
- Active Directory
Scripting (Preferred)
Preferred Certifications
One or more of the following:
- CEH (Certified Ethical Hacker)
- PNPT (Practical Network Penetration Tester)
- OSCP (Offensive Security Certified Professional)
- eJPT
- CompTIA Security+
- CISSP
Pay: ₹20,000.00 - ₹35,000.00 per month
Benefits:
- Health insurance
- Life insurance
Work Location: In person