Ethical Hacker / Application Security Expert - Red Team

Win Global PR

Bengaluru

On-site

INR 350,000 - 700,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Win Global PR is seeking an Application Security Expert to lead Red Team and ethical hacking efforts across web, mobile, and desktop applications. You will plan and execute realistic attack simulations, develop custom exploits, and conduct social engineering to test awareness and controls.

You will perform advanced penetration testing, review secure code from an offensive perspective, conduct vulnerability research, and advocate for secure SDLC integration.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science or Information Security.
  • 8+ years of experience in application security and red teaming.
  • Strong knowledge of OWASP Top 10 and related threats.
  • Experience with Metasploit, Burp Suite, Kali Linux.
  • Exploit development and reverse engineering.

Responsibilities

  • Plan and execute realistic attack simulations against web, mobile, and desktop apps.
  • Develop custom exploits to emulate threat actors.
  • Conduct social engineering campaigns to assess awareness.
  • Perform in-depth penetration tests with automated and manual techniques.
  • Provide remediation guidance and detailed reports.
  • Collaborate to integrate security testing into SDLC.

Skills

Python
Java
C
C++
OWASP Top 10
Cloud security
Authn/Authz
Web app architectures

Education

Bachelor's or Master's in CS/Info Security

Tools

Metasploit
Burp Suite
Kali Linux

Job description

Job Title: Application Security Expert - Red Team / Ethical Hacker

Department: Information Security / Cybersecurity

Reports To: Group CISO

Responsibilities
  • Red Teaming & Attack Simulation:
    • Plan and execute realistic attack simulations against our web, mobile, and desktop applications to identify weaknesses and bypass security controls.
    • Develop and utilize custom exploits, tools, and techniques to mimic the tactics, techniques, and procedures (TTPs) of advanced threat actors.
    • Conduct social engineering campaigns to assess employee awareness and identify potential vulnerabilities.
  • Advanced Penetration Testing:
    • Perform in-depth penetration tests of applications, networks, and systems, using both automated tools and manual techniques.
    • Identify and exploit complex vulnerabilities, including those related to application logic, authentication, authorization, and data handling.
    • Develop detailed penetration test reports with clear and actionable recommendations for remediation.
  • Secure Code Review (Offensive Perspective):
    • Conduct code reviews from an offensive perspective, identifying potential vulnerabilities that could be exploited by attackers.
    • Provide developers with guidance on secure coding practices and vulnerability remediation techniques.
    • Develop and maintain secure coding guidelines and checklists.
  • Vulnerability Research & Exploit Development:
    • Stay up-to-date on the latest security threats, vulnerabilities, and exploit techniques.
    • Conduct vulnerability research to identify new and emerging threats.
    • Develop custom exploits and tools to test and demonstrate the impact of vulnerabilities.
  • SDLC Integration & Security Advocacy:
    • Collaborate with development teams to integrate security testing and red teaming activities into the SDLC.
    • Participate in design reviews and provide security guidance on application architecture and design.
    • Promote a security-conscious culture within the development organization.
  • Vulnerability Management (Validation & Verification):
    • Validate and verify the effectiveness of vulnerability remediation efforts.
    • Retest remediated vulnerabilities to ensure they have been properly addressed.
  • Security Tooling & Automation (Offensive Tools):
    • Evaluate, recommend, and customize offensive security tools and technologies.
    • Automate red teaming and penetration testing processes to improve efficiency and coverage.
Education
  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
Experience
  • 8+ years of experience in application security, penetration testing, red teaming, or a related field.
  • Demonstrable experience conducting advanced penetration tests and red team engagements.
  • Strong understanding of web application vulnerabilities (e.g., OWASP Top 10, SANS Top 25).
  • Experience with various penetration testing tools and frameworks (e.g., Metasploit, Burp Suite, Kali Linux).
  • Experience with exploit development and reverse engineering.
Technical Skills
  • Expert proficiency in one or more programming languages (e.g., Python, Java, C, C++).
  • Strong understanding of web application architectures and technologies.
  • Deep understanding of network protocols and security concepts.
  • Familiarity with cloud security principles and practices (e.g., AWS, Azure, GCP).
  • Understanding of authentication and authorization mechanisms.
Certifications (Required/Preferred)
  • Offensive Security Certified Professional (OSCP) - Required
  • Certified Ethical Hacker (CEH) - Preferred
  • GIAC Web Application Penetration Tester (GWAPT) - Preferred
  • Offensive Security Certified Expert (OSCE) - Highly Preferred
  • Offensive Security Web Expert (OSWE) - Highly Preferred
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer - Red Team
Application Security Engineer - Red Team

Air India • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Cyber Security Expert
Cyber Security Expert

Trigyn Technologies • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Sr. Security Consultant
Sr. Security Consultant

Eventussecurity • Mumbai

On-site
INR 1,200,000 - 2,000,000
Red Team Specialist
Red Team Specialist

ESP Engineered • Mumbai

On-site
INR 1,200,000 - 2,000,000
Cutting-edge Red Team engagements
Collaborative environment
Continuous learning opportunities
Senior Manager - Information Security And Governance
Senior Manager - Information Security And Governance

HDB Financial Services Ltd. • Mumbai

On-site
INR 800,000 - 1,400,000
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Security Consultant - Red Team
Security Consultant - Red Team

Payatu • Bengaluru

On-site
INR 800,000 - 1,200,000
Security Architect
Security Architect

TechBlocks • Hyderabad

On-site
INR 2,000,000 - 3,500,000
Security Engineer - Red Team Operator / Engineer
Security Engineer - Red Team Operator / Engineer

PKF Algosmic Pvt Ltd • Maharashtra

On-site
INR 600,000 - 1,200,000