About the role
We are seeking a Senior Penetration Tester with 5-8 years of experience to lead advanced manual security assessments across web, mobile, APIs, and network environments. This role involves identifying vulnerabilities, guiding remediation efforts, and enhancing testing methodologies in a dynamic hybrid work setting.
Key responsibilities
- Lead scoping and execution of penetration testing engagements based on business risks and architecture assessments.
- Perform advanced manual testing of web, mobile (Android & iOS), API/Web services, network, and thick client applications.
- Validate vulnerabilities with hands-on exploitation and differentiate true risks from false positives.
- Deliver clear, risk-based remediation advice and prepare comprehensive technical reports and executive summaries.
- Leverage scripting, automation, and AI-assisted techniques to improve testing efficiency and support AI-enabled application security assessments.
Required skills and experience
- 5-8 years of hands-on experience in manual penetration testing across web applications, mobile platforms, APIs, and networks.
- Strong expertise in identifying and exploiting common vulnerabilities with practical experience in tools like Burp Suite, OWASP ZAP, Metasploit, SQLMap, Nmap, and Qualys.
- Proficient with Kali Linux or equivalent penetration testing platforms and scripting languages such as Python, Bash, or PowerShell.
- Solid understanding of OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK framework, and application security principles.
- Excellent analytical, troubleshooting, and communication skills to explain vulnerabilities and remediation to diverse stakeholders.
- Experience working in fast-paced, multi-stakeholder environments with a focus on quality and timely delivery.
Nice to have
- Knowledge of AI-assisted security testing, including LLM security, prompt injection, and misuse scenario validation.
- Familiarity with reverse engineering, cloud security testing, and static/dynamic application security testing (SAST/DAST) tools.
- Exposure to OWASP LLM Top 10 and secure coding practices with remediation validation.
- Relevant certifications such as OSCP, OSWE, OSEP, GPEN, GWAPT, GMOB, or eCPPT.
Location
Shaikpet, Telangana, India
Location :Hyderabad, Telangana, India