Role Overview
We are seeking a Security Engineer with 1-2 years of experience to perform end-to-end penetration testing across web applications, APIs, mobile platforms, and infrastructure. The role involves identifying and exploiting vulnerabilities, conducting Active Directory assessments, and performing reverse engineering to secure complex environments.
Responsibilities
- Perform end-to-end penetration testing (black-box, gray-box, white-box) on web, mobile, and infrastructure.
- Identify and exploit vulnerabilities including OWASP Top 10, SSRF, IDOR, and RCE.
- Conduct Active Directory security assessments and privilege escalation testing.
- Perform infrastructure penetration testing including network enumeration and firewall bypass.
- Conduct mobile application security testing using static and dynamic analysis.
- Perform thick client security testing and basic reverse engineering using tools like IDA/Ghidra.
- Develop proof-of-concept exploits and prepare detailed technical reports with CVSS ratings.
- Collaborate with DevOps and development teams to validate remediation.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- 1–2 years of hands-on experience in offensive security.
- Strong understanding of TCP/IP, DNS, and authentication protocols like Kerberos and OAuth.
- Familiarity with Windows & Linux privilege escalation.
- Mandatory certifications such as CEH or eJPT.
Skills
- Burp Suite
- Metasploit
- Nmap
- BloodHound
- OWASP Top 10
Benefits
- Salary: ₹500,000.00 - ₹600,000.00 per year