Cyber Threat Investigator

Unthinkable Solutions, LLC

Gurugram District

On-site

INR 1,200,000 - 1,800,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

VAPT & Red Teamer Specialist – Web, API, Network & Active Directory is sought for hands-on testing, reporting, and client communication. The role covers Web, API, Network and AD security testing with exploitation, attack-path analysis, and RoE compliance.

The candidate will utilize Burp Suite,Nmap,Nessus/Qualys,BloodHound,Impacket,Rubeus,Mimikatz,Certipy,Metasploit and scripting in Python/PowerShell/Bash to deliver actionable security findings and remediation guidance.

Qualifications

  • 3+ years of penetration testing/red teaming experience.
  • Hands-on Web, API, Network & AD testing expertise.
  • Strong proficiency with Burp Suite and security tools.
  • Practical AD enumeration, privilege escalation and attack paths.
  • Scripting in Python, PowerShell or Bash.

Responsibilities

  • Conduct VAPT and Red Team engagements across Web, API, Network, Internal Infrastructure, and Active Directory.
  • Perform manual/automated testing covering OWASP Top 10, authentication, authorization, injection, business logic, and data exposure.
  • Execute Red Team operations including recon, initial access, privilege escalation, lateral movement, persistence, and attack-path analysis.
  • Perform AD enumeration, privilege escalation, lateral movement, and attack-path analysis.
  • Use tools including Burp Suite, Nmap, Nessus/Qualys, BloodHound, Impacket, Rubeus, Mimikatz, Certipy, Metasploit.
  • Develop security automation/scripts using Python, PowerShell, or Bash.
  • Deliver technical reports with risk, evidence, reproduction, business impact, and remediation guidance.
  • Present findings to technical/non-technical stakeholders and support remediation validation.
  • Operate strictly within Rules of Engagement (RoE) and authorized scopes.

Skills

Web testing
API testing
Network testing
Active Directory
Burp Suite
Nessus/Qualys
BloodHound
Impacket
Mimikatz
Rubeus
Certipy
Metasploit
Python
PowerShell
Bash
Kali Linux
Adversary simulation

Education

OSCP
CRTE
CRTO

Tools

Burp Suite
Nmap
Nessus/Qualys
BloodHound
Impacket
Rubeus
Mimikatz
Certipy
Metasploit

Job description

VAPT & Red Teamer Specialist – Web, API, Network & Active Directory

Experience: 3–5 Years | Domain: Security Consulting

Role Overview

Seeking a hands-on Penetration Tester / Red Teamer experienced in Web, API, Network, and Active Directory security testing, with strong skills in exploitation, attack-path analysis, reporting, and client communication.

Key Responsibilities
  • Conduct VAPT and Red Team engagements across Web, API, Network, Internal Infrastructure, and Active Directory.
  • Perform manual/automated testing covering OWASP Top 10, authentication, authorization, injection, business logic, and data exposure.
  • Execute Red Team operations, including reconnaissance, initial access, privilege escalation, lateral movement, persistence, and attack-path analysis within authorized scope.
  • Perform AD enumeration, privilege escalation, lateral movement, and attack-path analysis.
  • Use tools including Burp Suite, Nmap, Nessus/Qualys, BloodHound, Impacket, Rubeus, Mimikatz, Certipy, and Metasploit.
  • Develop security automation/scripts using Python, PowerShell, or Bash.
  • Deliver technical reports with risk, evidence, reproduction, business impact, and remediation guidance.
  • Present findings to technical/non-technical stakeholders and support remediation validation.
  • Operate strictly within approved Rules of Engagement (RoE) and authorized scopes.
Must Have
  • 3+ years of penetration testing/red teaming experience.
  • Strong hands-on Web, API, Network & AD testing expertise.
  • Proficiency with Burp Suite and security testing tools.
  • Practical knowledge of AD enumeration, privilege escalation, lateral movement, and attack paths.
  • Scripting skills in Python, PowerShell, or Bash.
  • Strong reporting, communication, and client-facing skills.
  • Experience working under formal RoE.
Tools & Frameworks

Burp Suite | Nmap | Nessus/Qualys | BloodHound | Impacket | Rubeus | Mimikatz | Certipy | Metasploit | Python | PowerShell | Bash | Kali Linux

Frameworks: OWASP Top 10 | MITRE ATT&CK
Certifications

OSCP, CRTE, CRTO, or equivalent preferred.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Offensive Security Engineer(Red Team/Penetration Tester)
Senior Offensive Security Engineer(Red Team/Penetration Tester)

Systools Software • Pune District, Mumbai, Delhi

On-site
INR 1,400,000 - 2,800,000
Technical Lead-Cybersecurity
Technical Lead-Cybersecurity

Birlasoft • Dadri

On-site
INR 1,200,000 - 2,400,000
Senior Security Consultant
Senior Security Consultant

Eventus Security • Navi Mumbai

On-site
INR 1,500,000 - 2,500,000
Cyber Penetration Tester Senior
Cyber Penetration Tester Senior

Baker Tilly US • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Network Security
Network Security

Sisainfosec • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Penetration Tester
Penetration Tester

Michael Page • Hyderabad

Hybrid
INR 2,500,000 - 5,500,000
Cyber Analysts - Vulnerability Management and Penetration Testing
Cyber Analysts - Vulnerability Management and Penetration Testing

Tata Power • Navi Mumbai, Mumbai

On-site
INR 800,000 - 1,400,000
Penetration Tester (SMB)
Penetration Tester (SMB)

BreachLock, Inc. • Dadri

On-site
INR 1,200,000 - 2,400,000
Private Health Insurance
Penetration Tester (ME)
Penetration Tester (ME)

BreachLock, Inc. • Dadri

On-site
INR 1,200,000 - 2,400,000
Private Health Insurance