Jobgether
Jobgether

Penetration Testing

engineeringfull-timeIndia
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities

    • Execute penetration testing engagements across web applications, APIs, networks, and cloud environments with minimal supervision.

    • Assess applications and infrastructure using a combination of automated tools and manual testing techniques.

    • Identify, validate, exploit, and document security vulnerabilities with clear evidence and practical proof-of-concepts.

    • Evaluate vulnerabilities across areas such as authentication, authorization, injection, XSS, SQL injection, XXE, SSRF, deserialization, file inclusion, path traversal, and remote code execution.

    • Develop practical, risk-based remediation recommendations that help clients address identified security weaknesses.

    • Configure and operate penetration testing tools and develop supporting scripts or tooling where appropriate.

    • Produce accurate, high-quality, client-ready penetration testing reports with clear technical findings and business-relevant context.

    • Participate in client-facing activities, including scoping discussions, project kickoff calls, technical discussions, and report reviews.

    • Perform quality assurance reviews and peer reviews of security assessment deliverables.

    • Contribute to internal security research, tooling, testing methodologies, and continuous improvement initiatives.

    • Collaborate with other security professionals to maintain consistent delivery quality and share technical knowledge.

    • Handle sensitive client information responsibly, maintaining confidentiality and professionalism throughout engagements.

    • Requirements

      • 2–5 years of professional experience in penetration testing, offensive security, or a closely related cybersecurity discipline.

      • Industry-recognized offensive security certification or equivalent practical experience; certifications from organizations such as SANS, Offensive Security, or eLearnSecurity are valued.

      • Strong practical experience testing web applications and APIs, including REST, SOAP, XML, and JSON-based services.

      • Experience with thick-client applications and familiarity with modern web technologies and frameworks such as Angular and Bootstrap.

      • Strong understanding of computer networks, web and mobile applications, common security vulnerabilities, and established security frameworks such as the OWASP Top 10.

      • Knowledge of common CVEs and the ability to assess and exploit vulnerabilities in realistic environments.

      • Experience with vulnerabilities including XSS, SQL injection, XXE, SSRF, insecure deserialization, file inclusion/path traversal, authentication flaws, and remote code execution.

      • Ability to develop proof-of-concepts that clearly demonstrate the potential impact and exploitability of identified vulnerabilities.

      • Proficiency with scripting or automation languages such as Python, Bash, PowerShell, or similar.

      • Strong written and verbal communication skills, with the ability to explain technical security concepts to both technical and non-technical audiences.

      • Ability to work independently with limited oversight while also collaborating effectively within a distributed security team.

      • Strong attention to detail, analytical thinking, and commitment to producing accurate, high-quality client deliverables.

      • Benefits

        • Fully remote working opportunity within India.

        • Full-time employment.

        • Opportunity to work on diverse penetration testing engagements across applications, APIs, networks, and cloud environments.

        • Exposure to real-world cybersecurity challenges and a broad range of technologies and attack surfaces.

        • Opportunities to contribute to security research, internal tooling, and testing methodology improvements.

        • Collaborative environment with opportunities for peer learning, technical knowledge sharing, and professional development.

        • Client-facing experience across security assessments, scoping, kickoff sessions, and report reviews.

        • Opportunity to strengthen offensive security expertise while working on varied client environments.

✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Penetration Testing at Jobgether — Remote