Infrastructure Pentester – Active Directory / Internal Network
Company: Redfox Cybersecurity
Location: Mumbai, Maharashtra, India (On-site)
Experience Required: 1-2 Years
Employment Type: Full-time
Joining: Immediate joiner preferred
Location Preference: Mumbai-based candidates preferred
About Redfox Cybersecurity:
Redfox Cybersecurity is a leading global cybersecurity firm specializing in offensive security operations, threat intelligence, and advanced penetration testing services. With strategic offices in Mumbai (India), Toronto (Canada), Delaware (USA), and London (UK), we serve Fortune 500 companies, government agencies, and enterprises across North America, Europe, Asia-Pacific, and beyond. Our team of elite security professionals is dedicated to protecting organizations against evolving cyber threats through proactive security assessments and cutting-edge offensive security methodologies.
Our global presence enables us to deliver 24/7 security services and maintain deep expertise across diverse regulatory environments, industry sectors, and threat landscapes. As we continue to expand our operations in the Asia-Pacific region, we are seeking talented individuals to join our Mumbai office and contribute to our mission of making the digital world safer.
About the Role:
We are seeking a highly motivated Infrastructure Pentester with a strong focus on Active Directory and internal network security to join our offensive security team at our Mumbai office.
This role offers an opportunity to work on diverse and high-impact infrastructure security assessments for clients across multiple industries and geographies. The successful candidate will be responsible for assessing enterprise infrastructure, identifying weaknesses within Windows and Active Directory environments, and demonstrating realistic attack paths that could be leveraged by malicious actors.
You will work alongside seasoned security professionals from our global offices, gain exposure to complex enterprise environments, and have the opportunity to contribute to real-world security assessments that make a tangible difference in our clients' security posture.
The role provides exposure to international projects and the possibility of collaboration with our teams in Toronto, Delaware, and London, while offering opportunities to develop deeper expertise in infrastructure penetration testing, Active Directory security, and enterprise attack methodologies.
Key Responsibilities:
- Conduct comprehensive infrastructure penetration testing engagements across internal networks, Windows environments, Active Directory, and enterprise infrastructure
- Assess internal network architecture, segmentation, trust relationships, authentication mechanisms, and security controls
- Perform Active Directory security assessments, including enumeration, privilege escalation, lateral movement, and attack-path analysis
- Identify and exploit common Active Directory and Windows security weaknesses, misconfigurations, excessive privileges, and insecure authentication mechanisms
- Conduct network reconnaissance, service enumeration, vulnerability identification, exploitation, and post-exploitation activities
- Assess Windows servers, workstations, domain controllers, file servers, application servers, and other enterprise infrastructure
- Identify attack paths from low-privileged or compromised users to privileged accounts and critical infrastructure
- Perform credential-related assessments, including password security, credential exposure, authentication weaknesses, and credential reuse
- Analyze Active Directory configurations, Group Policy, permissions, delegation, trusts, and privileged access controls
- Perform lateral movement assessments using appropriate and authorized penetration testing techniques
- Utilize tools such as BloodHound, Impacket, NetExec/CrackMapExec, Mimikatz, Metasploit, PowerShell, Nmap, Responder, and other industry-standard security tools
- Conduct vulnerability assessment and exploitation across internal network services and infrastructure
- Validate the real-world impact of identified vulnerabilities while maintaining client-approved rules of engagement
- Develop detailed technical reports documenting vulnerabilities, attack paths, risk assessments, evidence, and actionable remediation recommendations
- Present technical findings and security recommendations to clients and stakeholders
- Collaborate with blue team and security operations teams to improve detection, prevention, and defensive capabilities
- Coordinate with global team members across different time zones on multi-regional infrastructure security projects
- Stay current with emerging infrastructure threats, Active Directory attack techniques, Windows security research, and offensive security methodologies
- Contribute to the development of internal tools, methodologies, playbooks, and penetration testing frameworks
- Participate in knowledge-sharing sessions and contribute to Redfox Cybersecurity Academy through technical content and training material
- Support business development activities through technical demonstrations, proof-of-concept engagements, and client discussions where required
Required Qualifications:
- 1-2 years of demonstrated hands-on experience in infrastructure penetration testing, internal network security assessments, and Active Directory security testing
- Strong understanding of Windows operating systems, Active Directory, domain environments, authentication mechanisms, and enterprise network architecture
- Hands-on experience with Active Directory enumeration, attack-path identification, privilege escalation, and lateral movement
- Proficiency with industry-standard penetration testing tools and frameworks such as BloodHound, Impacket, NetExec/CrackMapExec, Mimikatz, Metasploit, Nmap, Responder, and PowerShell
- Strong understanding of common Active Directory vulnerabilities, misconfigurations, privilege relationships, delegation issues, Group Policy weaknesses, and authentication-related security risks
- Strong understanding of TCP/IP, DNS, DHCP, SMB, LDAP, Kerberos, NTLM, RDP, WinRM, HTTP/HTTPS, and other common enterprise network protocols and services
- Experience performing network reconnaissance, service enumeration, vulnerability identification, exploitation, and post-exploitation
- Understanding of Windows privilege escalation techniques and common Windows security weaknesses
- Ability to identify and demonstrate realistic multi-stage attack paths within internal network environments
- Experience in vulnerability assessment, exploitation, and post-exploitation techniques
- Strong technical writing and documentation skills with attention to detail
- Excellent analytical, problem-solving, and critical thinking capabilities
- Ability to work independently and as part of a distributed global team
- Strong communication skills with the ability to explain technical findings and attack paths to both technical and non-technical audiences
- Professional demeanor and ability to interact effectively with clients
Optional Qualifications (Good to have):
- Experience conducting authenticated and unauthenticated internal network penetration tests
- Knowledge of Windows domain hardening and Active Directory defensive controls
- Experience with Kerberos attacks, NTLM attacks, delegation abuse, ACL abuse, and other Active Directory attack techniques
- Knowledge of Microsoft Entra ID / Azure AD security
- Experience assessing hybrid Active Directory and cloud identity environments
- Knowledge of network segmentation, firewall configurations, VPN infrastructure, and enterprise network security architecture
- Experience with vulnerability scanners such as Nessus, Qualys, OpenVAS, or similar platforms
- Experience with scripting and automation using Python, PowerShell, Bash, or Ruby
- Knowledge of Linux security and Linux-based enterprise infrastructure
- Familiarity with virtualization technologies such as VMware and Hyper-V
- Familiarity with compliance frameworks such as PCI-DSS, ISO 27001, GDPR, SOC 2, and HIPAA
- Published security research, technical blog posts, or conference presentations
- Contributions to open-source security tools or frameworks
- Experience working in cross-functional or international teams
What We Offer:
- Competitive compensation package aligned with global standards
- Opportunity to work with an internationally recognized cybersecurity team across four countries
- Exposure to challenging and diverse infrastructure security projects across multiple industries and geographies
- Access to world-class training programs, certifications, and professional development opportunities
- Collaborative work environment that encourages innovation and knowledge sharing
- Career progression opportunities within a rapidly growing global organization
- Potential for international assignments and cross-office collaborations
- Professional certification sponsorship and continuous learning budget
Equal Opportunity Employer:
Redfox Cybersecurity is an equal opportunity employer committed to building a diverse and inclusive workplace. We welcome candidates from all backgrounds, experiences, and perspectives. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin
Pay: ₹500,000.00 - ₹500,001.00 per year
Benefits:
Work Location: In person