Network Security

Sisainfosec

Bengaluru

On-site

INR 3,500,000 - 7,000,000

Full time

39 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Sisainfosec in Bengaluru seeks a senior offensive security professional to lead red team operations, adversary emulation, and cloud pentesting across AWS, Azure, and GCP. You will simulate attacker techniques, craft attack paths, bypass controls in authorized environments, and deliver actionable remediation guidance.

You will mentor juniors, contribute to playbooks, and present findings to clients and leadership with strong reporting and communication skills.

Qualifications

  • Senior offensive security expert with hands-on red team experience.
  • Demonstrated ability to perform enterprise security assessments and deliver actionable reports.
  • Proficiency in adversary emulation, exploit chaining, and credential theft simulations.
  • Strong knowledge of cloud penetration testing across AWS, Azure, GCP.

Responsibilities

  • Lead red team, adversary emulation, black-box network, cloud, and infrastructure testing engagements.
  • Plan and execute attack scenarios covering reconnaissance, initial access, exploitation, lateral movement and persistence.
  • Use adversary emulation platforms and C2 frameworks such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, Covenant in authorized assessments.
  • Design and execute phishing simulation campaigns, payload delivery, and initial access simulations.
  • Conduct Active Directory and hybrid identity attack simulations including credential attacks and domain escalation scenarios.
  • Perform cloud penetration testing across AWS, Azure, and GCP focusing on IAM abuse, misconfigurations, and privilege escalation paths.
  • Assess endpoint, network, identity, cloud, and email security controls from an attacker’s perspective.
  • Prepare detailed reports covering attack chains, weaknesses exploited, business impact, evidence, and remediation recommendations.
  • Present findings to technical teams, leadership and clients; mentor junior team members and contribute to playbooks.

Skills

Red Teaming
Adversary Emulation
Black-Box Testing
Network Penetration
Cloud Pentesting
Phishing Simulations
C2 Frameworks
MITRE ATT&CK
Exploit Development
Active Directory Attacks
Kerberoasting
Cloud IAM Attacks
Pentest Tools Knowledge
Python Scripting
OPSEC/Evasion

Education

OSCP / OSCE / GPEN / GXPN / PNPT / eCPPT or CEH

Tools

BloodHound
Mimikatz
Impacket
CrackMapExec
Nessus
Burp Suite
GoPhish
Nmap
Masscan
Pacu
ScoutSuite
AzureHound
ROADtools
Cobalt Strike
Sliver
Mythic
Havoc
Metasploit
Covenant

Job description

We are looking for a senior offensive security professional with strong expertise in red team operations, adversary emulation, black-box network penetration testing, cloud penetration testing, phishing simulations, C2 operations, and custom exploit development.

The role requires hands-on capability to simulate real-world attacker behavior, develop attack paths, bypass security controls in authorized environments, and deliver high-quality technical findings with practical remediation guidance.

Key Responsibilities
  • Lead red team, adversary emulation, black-box network, cloud, and infrastructure penetration testing engagements.
  • Plan and execute attack scenarios covering reconnaissance, initial access, exploitation, privilege escalation, lateral movement, persistence, and objective-based actions.
  • Use adversary emulation platforms and C2 frameworks such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, and similar tools in authorized assessments.
  • Design and execute phishing simulation campaigns, payload delivery scenarios, and initial access simulations.
  • Conduct Active Directory and hybrid identity attack simulations, including credential attacks, lateral movement, privilege escalation, and domain compromise scenarios.
  • Perform cloud penetration testing across AWS, Azure, and GCP, focusing on IAM abuse, exposed assets, storage misconfigurations, insecure networking, excessive permissions, and privilege escalation paths.
  • Assess endpoint, network, identity, cloud, and email security controls from an attacker’s perspective.
  • Support purple team and detection validation exercises by mapping techniques to MITRE ATT&CK.
  • Prepare detailed reports covering attack chains, exploited weaknesses, business impact, evidence, and remediation recommendations.
  • Present findings and attack narratives to technical teams, leadership, and client stakeholders.
  • Mentor junior team members and contribute to red team playbooks, tooling, labs, and methodologies.
Required Skills
  • Strong hands-on expertise in red teaming, adversary emulation, black-box testing, network penetration testing, and cloud pentesting.
  • Practical experience with C2 and adversary emulation platforms such as Cobalt Strike, Sliver, Mythic, Havoc, Metasploit, Covenant, or similar frameworks.
  • Experience in phishing simulations, payload delivery, social engineering assessments, and initial access simulation.
  • Ability to perform custom exploit development, exploit chaining, payload customization, and proof-of-concept creation.
  • Strong knowledge of Active Directory attack techniques, including Kerberoasting, AS-REP roasting, NTLM relay, pass-the-hash, pass-the-ticket, delegation abuse, ACL abuse, and domain escalation paths.
  • Good understanding of cloud attack techniques across AWS, Azure, and GCP, including IAM abuse, storage exposure, metadata service abuse, key leakage, role assumption, and privilege escalation.
  • Experience with tools such as BloodHound, Mimikatz, Impacket, NetExec/CrackMapExec, Responder, Evilginx, GoPhish, Nmap, Masscan, Nessus, Burp Suite, Wireshark, Hashcat, Hydra, Pacu, Prowler, ScoutSuite, AzureHound, ROADtools etc
  • Scripting and automation skills in Python, PowerShell, Bash, Go, or C/C++.
  • Good understanding of OPSEC, payload handling, evasion concepts, attack path mapping, and detection-aware testing.
  • Strong reporting, stakeholder communication, and client-facing skills.
Good to Have
  • Experience with EDR/AV evasion testing in authorized environments.
  • Experience with malware analysis, reverse engineering, or implant customization.
  • Exposure to Kubernetes, Docker, and container security assessments.
  • Experience conducting purple team exercises and detection engineering support.
  • Certifications such as OSCP, OSEP, GPEN, GXPN, PNPT, eCPPT or CEH.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SISA Information Security - Network Security Engineer
SISA Information Security - Network Security Engineer

SISA • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Principle Penetration Tester – Red Team Expert
Principle Penetration Tester – Red Team Expert

engineersmind • Pune District

On-site
INR 3,000,000 - 4,600,000
Red Team Specialist
Red Team Specialist

ESP Engineered • Mumbai

On-site
INR 1,200,000 - 2,000,000
Cutting-edge Red Team engagements
Collaborative environment
Continuous learning opportunities
Cyber Security Senior Engineer
Cyber Security Senior Engineer

Evernorth Health Services • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Penetration Testing Senior Consultant
Penetration Testing Senior Consultant

Alignity Solutions • Hyderabad

Hybrid
INR 1,800,000 - 3,000,000
Hybrid work
Senior Penetration Tester
Senior Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Hybrid Working
Senior Manager - Information Security And Governance
Senior Manager - Information Security And Governance

HDB Financial Services Ltd. • Mumbai

On-site
INR 800,000 - 1,400,000
Senior Red Team Engineer
Senior Red Team Engineer

SolarWinds • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Sr. Security Consultant
Sr. Security Consultant

Eventussecurity • Mumbai

On-site
INR 1,200,000 - 2,000,000