Penetration Tester

JAGGAER

Hyderabad

On-site

INR 1,500,000 - 2,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health
Accidental Insurance
Term Life

Job summary

JAGGAER in Hyderabad, India, is seeking a Penetration Tester to lead hands-on offensive security testing across our SaaS platforms and infrastructure. You will identify vulnerabilities before attackers do, including AI-powered features, and communicate risk to technical and non-technical stakeholders.

You'll develop novel attack techniques, build automation, and validate remediation across the SDLC, while promoting an attacker’s-eye view of risk and security culture within engineering teams.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent practical experience.
  • 3+ years of hands-on penetration testing experience across web, network, and cloud environments.

Responsibilities

  • Plan, scope, and execute penetration tests across the full portfolio of JAGGAER applications, platforms, APIs, internal and external networks, and cloud environments (GCP, AWS, Azure).
  • Go beyond standard methodology; develop novel, custom attack techniques and proof-of-concept exploits.
  • Build automation and tooling to scale testing coverage across a large product portfolio.
  • Embed AI-assisted techniques into the testing workflow and validate AI-generated results.
  • Conduct authenticated and unauthenticated testing of multi-tenant SaaS environments.
  • Design red-team style exercises and validate detection and response capabilities.
  • Translate findings into actionable remediation guidance and retest to confirm fixes.
  • Support the Vulnerability Disclosure Program by validating externally reported findings.
  • Assess software supply chain risk and dependency risk from attacker perspective.
  • Coordinate third-party pentesting engagements ensuring scope and quality.
  • Produce clear, well-evidenced reports with risk ratings and remediation guidance.
  • Maintain test tooling and stay current with emerging attack techniques.
  • Promote an attacker-eye-view of risk across engineering teams.

Skills

Python
Web security testing
Cloud security
AI-assisted security testing
Communication

Education

Bachelor's degree in Computer Science or related field

Tools

Python scripting
OWASP testing

Job description

Overview

About JAGGAERJAGGAER provides an intelligent Source-to-Pay and Supplier Collaboration Platform that empowers organizations to manage and automate complex processes while enabling a highly resilient, responsible, and integrated supplier base. With 30 years of expertise, we specialize in solving complex procurement and supply chain challenges across various industries.

Our 1,200+ global employees are obsessed with ensuring customers get full value from our products—ultimately enhancing and transforming their businesses.For more information, visit www.jaggaer.com

Product Security EngineerAI & Application Security | Cyber Architecture & Defense

Penetration TesterOffensive Security | Cyber Architecture & Defense

OverviewWhy Consider JAGGAER?JAGGAER is the world's leading provider of comprehensive source-to-pay solutions. Some of the largest commercial, manufacturing, and life sciences companies, and government organizations in the world, trust JAGGAER with billions of dollars of annual spend. JAGGAER eProcurement and strategic sourcing customers across the globe have gained access to the best suppliers, with the best terms, on our scalable, customizable, user-friendly platform. Our SaaS-based, source-to-settle solution provides unparalleled visibility, insights, and recommendations to procurement leaders and suppliers, driving a fluid supply chain through powerful spend analysis, comprehensive contract management, and efficient accounts payable solutions.

What We’re Looking ForReporting to the Director of Cyber Architecture & Defense, we are seeking a Penetration Tester to lead hands-on offensive security testing across the full portfolio of JAGGAER applications, platforms, and infrastructure - including our AI-powered and agentic capabilities. This role works closely with our Product Security Engineer and development teams to identify exploitable vulnerabilities before attackers do, through internal and external network testing, web application and API testing, cloud configuration testing, and adversarial testing of AI/ML-integrated features. We’re looking for someone who goes beyond checklist-driven testing - who thinks like a real adversary, develops novel attack techniques tailored to our specific applications, and builds the automation and tooling - including AI-assisted testing workflows - needed to scale that creativity across a large and growing product portfolio. You will plan and execute engagements independently, clearly communicate risk and business impact to both technical and non-technical stakeholders, and help validate remediation efforts across the SDLC.

Principal Responsibilities

Principal ResponsibilitiesAwesome Things You’ll Do

  • Plan, scope, and execute penetration tests across the full portfolio of JAGGAER applications, platforms, APIs, internal and external networks, and cloud environments (GCP, AWS, Azure), applying frameworks such as the OWASP Top 10, OWASP API Security Top 10, and MITRE ATT&CK - including AI-powered and agentic features, where risks such as prompt injection, insecure output handling, and excessive agency are assessed against the OWASP LLM Top 10 and OWASP Agentic AI Top 10.
  • Go beyond standard methodology and known CVEs - think creatively about how JAGGAER's specific applications, integrations, and business logic could be abused, and develop novel, custom attack techniques and proof-of-concept exploits tailored to those scenarios.
  • Build automation and tooling to scale testing coverage and repeatability across a large, growing, and constantly-changing application and platform portfolio, rather than relying solely on manual, point-in-time assessments.
  • Embed AI-assisted techniques into the testing workflow itself - using LLM-driven and "vibe testing" approaches to accelerate reconnaissance, test case and payload generation, fuzzing, and triage - while validating AI-generated results before acting on them.
  • Conduct authenticated and unauthenticated testing of multi-tenant SaaS environments, identifying cross-tenant and privilege-escalation risks.
  • Design and run red-team style exercises and attack simulations to validate detection and response capabilities in partnership with security operations.
  • Partner with the Product Security Engineer and development teams to translate findings into actionable, risk-prioritized remediation guidance, and retest to confirm fixes.
  • Support the Vulnerability Disclosure Program (VDP) by validating and reproducing externally reported findings and assessing real-world exploitability.
  • Assess software supply chain and dependency risk from an attacker's perspective, including exploitability of vulnerable third-party and open-source components.
  • Coordinate and provide oversight of third-party penetration testing engagements, ensuring scope, quality, and findings meet internal and customer/compliance expectations.
  • Produce clear, well-evidenced reports for technical and executive audiences, including risk ratings, exploitation narratives, and remediation guidance.
  • Maintain test tooling, attack infrastructure, and internal methodologies, keeping pace with emerging attack techniques.
  • Serve as a security champion, promoting an attacker's-eye-view of risk and offensive security awareness across engineering and product teams.
  • Maintain functional understanding of common compliance frameworks relevant to testing scope and cadence, including NIST 800-53, PCI DSS, SOC 2 Type II, and CSA CCM.
Position Requirements

What You Will Bring

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • 3+ years of hands-on experience performing penetration tests or red team engagements across web applications, networks, and cloud environments.
  • Proficient in at least one scripting or programming language (e.g., Python) for tooling, exploit development, and automation at scale.
  • Demonstrated ability to think beyond established methodology - chaining findings, abusing business logic, and developing original attack paths rather than relying only on known tools and signatures.
  • Comfort using AI-assisted and "vibe testing" workflows (e.g., LLM-driven test generation, fuzzing, or triage) to accelerate offensive testing, paired with the judgment to critically validate AI-generated output.
  • Strong understanding of web application, API, network, and cloud security across multi-cloud environments (GCP, AWS, Azure).
  • Familiarity with AI/LLM security concepts and agentic AI systems (e.g., prompt injection, model supply chain risk) is a strong plus, as testing scope spans the full JAGGAER application and platform portfolio, including AI-powered features.
  • Experience validating findings from a Vulnerability Disclosure Program (VDP) or bug bounty program is a plus.
  • Strong written and verbal communication skills, with the ability to translate technical findings into business risk for varied audiences.
  • Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN), Certified Ethical Hacker (CEH), or similar hands‑on offensive security certifications are a plus.

What We Offer: At JAGGAER, we are committed to supporting you and your family’s well‑being. Your health is a priority, and we offer a range of programs to help you stay well and thrive. Our benefits include Health, Accidental Insurance, and Term Life.

Our Values - T.E.A.M: At JAGGAER, our business is about people. Our products are built on intellectual property, but the real differentiator is the teams behind them - the way we collaborate, innovate, solve problems and deliver for customers. TEAM gives us a common set of expectations for how we work together across products, cultures, and geographies.

  • Transparency - Openness Builds Trust: Candor strengthens relationships, speeds decision‑making, and ensures problems are solved together—with customers, teammates, and partners.
  • Entrepreneurial Spirit - Own It, Drive It, and Make It: A scrappy, customer obsessed, problem‑solving mindset is at the cornerstone of both organizational and personal growth.
  • Accountability - Thumbs In, Not Fingers Out: We take responsibility ourselves before pointing elsewhere.
  • Metrics-Driven Results - Outcomes Over Activities: Data and evidence guide our decisions, help us course‑correct quickly, and ensure we’re delivering real impact.

EEO: JAGGAER is a proud equal opportunity/affirmative action employer supporting workforce diversity. We do not discriminate based upon race, ethnicity, ancestry, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), marital status, caregiver status, sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, genetic information, military, or veteran status, mental or physical disability, or other applicable legally protected characteristics.#LI-AR1

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

Jaggaer • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Health insurance
Accidental Insurance
Term Life
Vulnerability Analyst
Vulnerability Analyst

JAGGAER • Hyderabad

On-site
INR 800,000 - 1,500,000
Health insurance
Accidental Insurance
Term Life
Penetration Tester@ Jaggaer, Hyderabad
Penetration Tester@ Jaggaer, Hyderabad

JAGGAER • Hyderabad

Hybrid
INR 1,500,000 - 2,100,000
Principal Data Scientist
Principal Data Scientist

JAGGAER • Hyderabad

On-site
INR 5,000,000 - 7,500,000
Health benefits
Accidental Insurance
Term Life
Cloud Engineer
Cloud Engineer

JAGGAER • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Health Insurance
Accidental Insurance
Term Life
Digital Marketing Manager
Digital Marketing Manager

JAGGAER • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Health Insurance
Accidental Insurance
Term Life
Principal Data Scientist
Principal Data Scientist

JAGGAER • Telangana

On-site
INR 3,500,000 - 6,000,000
Health insurance
Accidental Insurance
Term Life
SW Engineer -- Workato Integrations
SW Engineer -- Workato Integrations

JAGGAER • Hyderabad

On-site
INR 1,500,000 - 2,600,000
Health insurance
Accidental Insurance
Term Life
Product Marketing Manager
Product Marketing Manager

JAGGAER • Hyderabad

Hybrid
INR 1,500,000 - 2,500,000
Health
Accidental Insurance
Term Life
Product Marketing Manager
Product Marketing Manager

JAGGAER • Telangana

Hybrid
INR 2,500,000 - 4,000,000
Health
Accidental Insurance
Term Life