An application made for this job — a tailored resume and cover letter that speak straight to the posting.
MCXCCL in Mumbai seeks an experienced Offensive Security Expert - Red Team to proactively identify and exploit security vulnerabilities across the SDLC. You will operate as a key member of the in‑house Red Team, conducting advanced penetration testing and real‑world attack simulations to strengthen our security posture.
The role requires 5–10 years in application security, with proficiency in tools like Metasploit, Burp Suite and Kali Linux, plus relevant certifications such as OSCP/ CEH.
You cannot push anyone up the Ladder unless the person is willing to Climb. At MCXCCL we sharpen your career growth path for you to Excel.
Full time B.E./ B.Sc (IT)/ BCA/ MCA/ M.sc (IT)/ other graduates with relevant experience.
5 - 10
Job Summary:
The Offensive Security Expert - Red Team/ Offensive Security/ Ethical Hacker, responsiblefor proactively identifying and exploiting security vulnerabilities in our software applicationsthroughout the entire Software Development Life Cycle. Operating as a key member of thein-house Red Team, this role will focus on conducting advanced penetration testing,simulating real-world attacks, and providing actionable intelligence to strengthen our overallsecurity posture.
Responsibilities:
Advanced Penetration Testing:
Perform in-depth penetration tests of applications, systems, and networks,using both manual techniques and automated tools.
Identify and exploit complex vulnerabilities, including those related toapplication logic, authentication, authorization, and data handling.
Develop detailed penetration test reports with clear and actionablerecommendations for remediation.
Red Teaming & Breach Attack Simulation:
Plan and execute realistic attack simulations against our web, mobile, anddesktop applications to identify weaknesses and bypass security controls.
Develop and utilize custom exploits, tools, and techniques to mimic thetactics, techniques, and procedures (TTPs) of advanced threat actors.
Conduct social engineering campaigns to assess employee awareness andidentify potential vulnerabilities.
Excellent Problem solving, Organizational skills and attention to details.
Conduct code reviews from an offensive perspective, identifying potentialvulnerabilities that could be exploited by attackers.
Provide developers with guidance on secure coding practices and vulnerabilityremediation techniques.
Develop and maintain secure coding guidelines and checklists.
Vulnerability Research & Exploit Development:
Confidentialo Stay up to date on the latest security threats, vulnerabilities, and exploittechniques.o Conduct vulnerability research to identify new and emerging threats.
Develop custom exploits and tools to test and demonstrate the impact ofvulnerabilities.
SDLC Integration:
Collaborate with development teams to integrate security testing and redteaming activities into the SDLC.o Participate in design reviews and provide security guidance on applicationarchitecture and design.o Promote a security conscious culture within the development organization.Vulnerability Management (Validation & Verification):o Validate and verify the effectiveness of vulnerability remediation efforts.o Retest remediated vulnerabilities to ensure they have been properly addressed.Security Tooling & Automation (Offensive Tools):o Evaluate, recommend, and customize offensive security tools andtechnologies.o Automate red teaming and penetration testing processes to improve efficiencyand coverage. Experience and Skills:o 5 to 10 years of experience in application security, penetration testing, redteaming, or a related field.o Demonstrable experience conducting advanced penetration tests and red teamengagements.o Strong understanding of web application vulnerabilities (e.g., OWASP Top10, SANS Top 25).o Experience with various penetration testing tools and frameworks (e.g.,Metasploit, Burp Suite, Kali Linux).o Experience with exploit development and reverse engineering.o Expert proficiency in one or more programming languages (e.g., Python, Java,.NET, C++).o Strong understanding of web application architectures and technologies.o Deep understanding of network protocols and security concepts.o Understanding of authentication and authorization mechanisms.o Certifications (Preferred)- OSCP, CEH, GWAPT, OSCE, OSWE etc.